Skip to main content
TrustEdge AI
Deployment platform

Azure OpenAI (Microsoft Foundry)

Deployment platform. Hosts OpenAI models in Microsoft's Azure environment under Microsoft's commercial terms — frequently the compliant route to a model whose direct API is not.

6 of 7 criteria carry a sourced value · 1 recorded as a gap ·  Verified August 8, 2026

What this means for a regulated buyer

Our analysis, not Azure OpenAI (Microsoft Foundry)’s. Every statement here traces to a sourced claim further down the page.

The compliance terms are Microsoft’s and the safety grade is OpenAI’s — which is precisely why running a model through a platform can be the compliant route to a model whose direct API is not.

Where it is strong

  • The HIPAA BAA is available by default through the Online Services Data Protection Addendum to all covered entities, rather than on request.
  • Six months’ advance notice before a new sub-processor is authorised — the longest committed notice period of any vendor tracked here.
  • Prompts and completions are explicitly not shared with the model provider, and the models are stateless.
  • Abuse-monitoring storage can be switched off for approved customers, and the state is independently verifiable via the ContentLogging attribute.

What to check or negotiate

  • Modified abuse monitoring must be applied for and approved; until then prompts and completions may be stored and human-reviewed.
  • Automated review may continue even after storage is switched off.
  • Global and DataZone deployment types change where processing occurs — check the deployment type against your data-residency commitments.
  • Microsoft states plainly that a BAA does not by itself achieve HIPAA compliance for the customer.

Verdict

The most straightforward BAA path of any row here. The diligence work is in deployment type and abuse-monitoring configuration, not in obtaining the agreement.

The full record

Every criterion, with Azure OpenAI (Microsoft Foundry)’s own wording where it is hedged or carries exclusions, the primary source, and the date we last read it.

FLI safety grade

Safety-research posture, per the Future of Life Institute

Not applicable

FLI grades model developers, not deployment platforms. The safety grade that bears on this row belongs to the model developer (OpenAI); the compliance terms below are Microsoft's. That split is the reason this tracker separates the two row kinds.

Primary source · verified 2026-08-04

BAA available

Will they sign a business associate agreement for PHI

Yes

Microsoft: the HIPAA BAA "is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA." Azure and Azure Government are named in the in-scope services list. Microsoft also states plainly that a BAA does not by itself achieve HIPAA compliance for the customer.

Primary source · verified 2026-08-04

Certifications

Independently audited attestations

ISO/IEC 27001 · HITRUST CSF · FedRAMP (Azure P-ATO from the JAB)

Microsoft: services covered under the BAA "undergo audits conducted by accredited independent auditors for the Microsoft ISO/IEC 27001 certification and the HITRUST Common Security Framework (CSF) certification." Audit reports are obtained through the Service Trust Portal.

Primary source · verified 2026-08-04

Trains on your data

Whether your inputs and outputs feed model training

Not by default — No training use without customer permission or instruction; prompts and completions are not shared with the model provider.

Microsoft states prompts, completions, embeddings and training data "are NOT available to OpenAI or other providers of Models sold by Azure", "are NOT used by providers... to improve their models or services", and "are NOT used to train any generative AI foundation models without your permission or instruction." Also: "The models are stateless: no prompts or completions are stored in the model."

Primary source · verified 2026-08-04

Retention

How long your data is kept, and where

Prompts and completions may be stored for abuse monitoring and human review; approved customers can have that storage and review switched off.

Modified abuse monitoring must be applied for and approved. Once approved, "the data storage and human review process described above is not performed", though automated review may continue. Customers can verify the state via the ContentLogging attribute in the Azure portal or CLI, which appears as "false" only when storage is off. Data stored at rest sits in the customer's Azure tenant within their designated geography; Global and DataZone deployment types change where processing occurs.

Primary source · verified 2026-08-04

Subprocessors

Who else processes your data

Named list covering all Microsoft Online Services, with at least six months’ advance notice before a new sub-processor is authorised.

Microsoft: "Microsoft publishes the names of any new subprocessors for its online services at least six months in advance of the subprocessor’s authorization to perform services that may involve access to customer data or personal data." The longest advance-notice commitment of any vendor tracked here. The list "is applicable for all Microsoft Online Services governed by the Microsoft Data Protection Addendum"; notification is via the Service Trust Portal’s My library rather than a separate subscription.

Primary source · verified 2026-08-07

EU AI Act

Obligations, and which transfer to you as deployer

Microsoft is a signatory to the EU General-Purpose AI Code of Practice, the voluntary route to demonstrating compliance with the AI Act.

The signatory here is Microsoft, the platform operator. OpenAI, whose models this platform hosts, is separately a signatory in its own right. Both rows carry the commitment independently, which is the distinction this tracker exists to keep visible.

Primary source · verified 2026-08-07

This is a deployment platform, so it carries no FLI safety grade — FLI grades model developers. The safety grade that bears on your deployment belongs to whichever model you run here; the compliance terms above are the platform’s and apply regardless of that choice.

Hosts models from OpenAI. Running one of those models here means the safety grade is theirs and the terms above are this platform’s.

Safety grades come from the FLI AI Safety Index, Summer 2026 — what it measures, and what it explicitly does not.

Deploying Azure OpenAI (Microsoft Foundry) in a regulated environment

We help regulated organisations build AI vendor diligence that holds up in an audit.