Every criterion, with Azure OpenAI (Microsoft Foundry)’s own wording where it is hedged or carries exclusions, the primary source, and the date we last read it.
FLI safety grade
Safety-research posture, per the Future of Life Institute
Not applicable
FLI grades model developers, not deployment platforms. The safety grade that bears on this row belongs to the model developer (OpenAI); the compliance terms below are Microsoft's. That split is the reason this tracker separates the two row kinds.
Primary source · verified 2026-08-04
BAA available
Will they sign a business associate agreement for PHI
Yes
Microsoft: the HIPAA BAA "is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA." Azure and Azure Government are named in the in-scope services list. Microsoft also states plainly that a BAA does not by itself achieve HIPAA compliance for the customer.
Primary source · verified 2026-08-04
Certifications
Independently audited attestations
ISO/IEC 27001 · HITRUST CSF · FedRAMP (Azure P-ATO from the JAB)
Microsoft: services covered under the BAA "undergo audits conducted by accredited independent auditors for the Microsoft ISO/IEC 27001 certification and the HITRUST Common Security Framework (CSF) certification." Audit reports are obtained through the Service Trust Portal.
Primary source · verified 2026-08-04
Trains on your data
Whether your inputs and outputs feed model training
Not by default — No training use without customer permission or instruction; prompts and completions are not shared with the model provider.
Microsoft states prompts, completions, embeddings and training data "are NOT available to OpenAI or other providers of Models sold by Azure", "are NOT used by providers... to improve their models or services", and "are NOT used to train any generative AI foundation models without your permission or instruction." Also: "The models are stateless: no prompts or completions are stored in the model."
Primary source · verified 2026-08-04
Retention
How long your data is kept, and where
Prompts and completions may be stored for abuse monitoring and human review; approved customers can have that storage and review switched off.
Modified abuse monitoring must be applied for and approved. Once approved, "the data storage and human review process described above is not performed", though automated review may continue. Customers can verify the state via the ContentLogging attribute in the Azure portal or CLI, which appears as "false" only when storage is off. Data stored at rest sits in the customer's Azure tenant within their designated geography; Global and DataZone deployment types change where processing occurs.
Primary source · verified 2026-08-04
Subprocessors
Who else processes your data
Named list covering all Microsoft Online Services, with at least six months’ advance notice before a new sub-processor is authorised.
Microsoft: "Microsoft publishes the names of any new subprocessors for its online services at least six months in advance of the subprocessor’s authorization to perform services that may involve access to customer data or personal data." The longest advance-notice commitment of any vendor tracked here. The list "is applicable for all Microsoft Online Services governed by the Microsoft Data Protection Addendum"; notification is via the Service Trust Portal’s My library rather than a separate subscription.
Primary source · verified 2026-08-07
EU AI Act
Obligations, and which transfer to you as deployer
Microsoft is a signatory to the EU General-Purpose AI Code of Practice, the voluntary route to demonstrating compliance with the AI Act.
The signatory here is Microsoft, the platform operator. OpenAI, whose models this platform hosts, is separately a signatory in its own right. Both rows carry the commitment independently, which is the distinction this tracker exists to keep visible.
Primary source · verified 2026-08-07