The country your AI runs in
Find out where your AI vendor actually processes your work, what pinning it to one region costs, and how to answer a client's residency question without guessing.
on this page · 0 / 0 checked
Sooner or later a client sends over a security questionnaire with a line asking where their data is processed. You know which AI tools you use. You probably know whether the tier you pay for is trained on. You almost certainly do not know which country the model was running in when it read the contract you pasted into it last Tuesday, and the honest answer for most small operators on default settings is that it could have been any of them.
Geography is a separate question from retention, and it has separate answers. This guide covers what the vendors a small operator actually uses will commit to about location, what pinning your work to one region costs in money and in model versions, and the markets where no setting will help you. It is not legal advice. If you work under a regime that names its own approved suppliers, in health, defence, or public-sector procurement, you need a lawyer and a signed data processing agreement, not a web guide. This is for the freelancer or the four-person team who has to put a real answer in a client’s spreadsheet by Friday.
Storage and processing are two different promises
Every vendor’s residency page draws a line that most readers skim past. One promise is about where your data sits when nothing is happening to it. The other is about where it goes when a model reads it. They are sold separately, priced separately, and only the second one answers what your client is asking.
Microsoft states it most plainly. On Microsoft Foundry, “Data stored at rest remains in the designated Azure geography”, but inference is a different matter: Global deployments may be processed in any Azure region, Data Zone deployments process data “only within the Microsoft-specified data zone (US, EU, or Asia Pacific (APAC))”, and Standard deployments process prompts and responses “within the customer-specified Azure geography” and may move them between regions inside it for operational reasons [6]. Same product, three tiers, three different truthful answers about where your prompt went.
OpenAI’s residency table has the same split, marked region by region. Of the 10 regions listed, the United States, Europe (EEA and Switzerland), and the United Arab Emirates are marked for storage and processing. Australia, Canada, Japan, India, Singapore, South Korea, and the United Kingdom are marked storage only [1]. Anthropic splits the same idea into two independent controls: an inference_geo parameter that “Controls where model inference runs on a per-request basis”, and a workspace geo that “Controls where data is stored at rest and where endpoint processing (such as image transcoding and code execution) happens” [3].
Google’s Gemini API terms make no location promise at all. Even on the paid tier, where Google retains prompts, responses and logs for safety and security purposes, the terms state that this data “may be stored transiently or cached in any country in which Google or its agents maintain facilities” [5]. That is not evasion, it is an accurate description of how a global inference fleet works when nobody has asked it to behave otherwise.
The map is smaller than the world
Once you filter for processing rather than storage, the list of places your work can legally and technically run gets short.
On OpenAI’s API, processing is available in 3 of the 10 named regions [1]. On the first-party Claude API, inference_geo accepts "global" or "us", and for storage the documentation is blunt: "us" is currently the only available workspace geo [3]. Microsoft’s data zones are US, EU, and APAC [6]. If a client wants processing done in Canada specifically, the honest answer today is that Canada is on OpenAI’s list for storage only [1]. Brazil and South Africa are not on that list in either column.
There is a second cost hiding in the same paragraphs, and it is model recency. Anthropic’s inference_geo parameter is supported on Claude 4.6 and later models, and requests using it against Claude Opus 4.5, Sonnet 4.5, Haiku 4.5 or earlier return a 400 error [3]. Microsoft is equally direct that “Global deployments receive new models and features first”, and that Global Standard “has the lowest price, and offers the broadest region coverage” [6]. Regional deployment is where the newest capability arrives last. When you promise a client a region, you are also promising them a slightly older stack, and you should say so before they notice.
Routing matters too. Anthropic’s residency controls apply to the first-party API and to Claude on AWS, while Bedrock and Google Cloud determine region by the endpoint you call, Claude in Microsoft Foundry uses the US Data Zone Standard deployment type instead, and the OpenAI SDK compatibility endpoint does not support the parameter at all [3]. The same model, bought through four channels, gives you four different mechanisms for the same promise.
You buy geography at setup, and it costs about 10 percent
The price of a region is not hidden, it is just never on the pricing page you read first.
OpenAI’s documentation states that “Data residency endpoints are charged a 10% uplift for models released on or after March 5, 2026, that are eligible for data residency” [1]. Anthropic prices US-only inference at “1.1x the standard rate across all token pricing categories (input tokens, output tokens, cache writes, and cache reads)”, and the same multiplier applies to the US Data Zone Standard route through Microsoft Foundry [3]. Two independent vendors, two documents, the same number. Treat 10 percent as the going rate for knowing where your tokens are.
The bigger cost is that geography is a setup decision. OpenAI’s residency is a project configuration option, chosen “from the dropdown when creating a new project”, with eligibility gated behind a conversation with their sales team [1]. Anthropic’s workspace geo is set when you create the workspace and cannot be changed afterward [3]. Neither of those is a switch you flip on the afternoon the questionnaire arrives. If there is any chance a client will ask, create the project in the region before the work starts, not after.
Read the exclusions in the same sitting. OpenAI’s residency stores your customer content at rest in the selected region “to the extent the endpoint requires data persistence to function”, and the same page notes that residency “does not apply to system data, which may be processed and stored outside the selected region”, defining system data as account data, metadata and usage data that do not contain customer content [1]. It also excludes anything that leaves the region because of where an end user or your own infrastructure sits when accessing the service [1]. Every residency product has carve-outs shaped like those. They are normally the logging, the metadata, and the operational telemetry, which is to say the layer nobody thinks to ask about until an auditor does.
10% is OpenAI's stated uplift for eligible models released on or after 5 March 2026 [1]; Anthropic prices US-only inference at 1.1x [3]. Computed in the page; nothing is sent anywhere.
The obligation follows your user, not your server
The instinct is to think of jurisdiction as a property of where you are. In practice it attaches to where the person typing is.
Google’s Gemini API terms say it in one line: “You may use only Paid Services when making API Clients available to users in the European Economic Area, Switzerland, or the United Kingdom” [5]. Nothing about where you live or where your server sits. If your side project has European users and runs on the free tier, you are outside the terms already. The same document explains why the free tier is not a neutral starting point: on unpaid services Google uses what you submit and what the model returns “to provide, improve, and develop Google products and services and machine learning technologies”, human reviewers “may read, annotate, and process your API input and output”, and the terms tell you plainly, “Do not submit sensitive, confidential, or personal information to the Unpaid Services” [5].
China’s rules are built on the same principle, taken further. The Interim Measures for the Management of Generative AI Services, in force since 15 August 2023, apply “to the use of generative AI technologies to provide services to the public in the [mainland] PRC for the generation of text, images, audio, video, or other content” [7]. The trigger is the audience, not the incorporation. Providers whose services have “public opinion properties or the capacity for social mobilization” must carry out security assessments and perform filing formalities for their algorithms [7]. That is a registration step, done before launch, on a regulator’s timetable rather than yours.
Even your contract moves with your customer. Anthropic’s Commercial Terms set the governing law by where the customer is: Ireland for the EEA, Switzerland and the UK, and California for everyone else [4]. You did not pick that. Your customer’s address did.
Some markets are not a configuration option
There is a point past which localization stops being a setting and becomes a second product, and the vendors show you exactly where that line is by simply not crossing it.
Mainland China does not appear on OpenAI’s list of countries and territories that currently support access to its API services [2]. That is the whole answer for a small operator with a prospective client in Shanghai. There is no region to select, no uplift to pay, and no support ticket that changes it. Serving that market with generative AI means a different provider under a different regime, with a filing step [7], different model behaviour, and a second set of prompts and evaluations to maintain forever. Price it as a product line, not a checkbox on a market-entry plan.
The reverse case runs the same way. A footnote on Apple’s own Apple Intelligence page states that “Siri AI will not initially be available in the EU on iOS, iPadOS and watchOS” [8]. A company with more control over its stack than almost anyone in consumer technology answered a jurisdiction’s rules by withholding a feature from it. When the largest vendors respond to regulatory divergence by shipping different products in different places, an assumption that your one API key travels everywhere is not caution, it is optimism.
Sanctions and export rules sit in the same bucket, and the obligation is pushed down to you. Anthropic’s terms state that “Customer may not export or provide access to the Services to persons or entities or into countries or for uses where it is prohibited under U.S. or other applicable international law”, a restriction that reaches countries requiring export licences and entities subject to U.S. sanctions programmes [4]. If you resell an AI-backed service, that clause is yours to enforce against your own customer list, not something the vendor handles quietly upstream.
The four questions that settle a security review
Ask which region does the processing, not which region does the storage, and get the answer in the vendor’s own words from their own documentation page rather than from a salesperson [1][6]. If the honest answer is “global”, say “global”. A client can live with a real answer and cannot live with one that turns out to be wrong.
Ask what is excluded. Every residency promise has a carve-out for system data, telemetry, or caching [1][5]. Write the carve-out into your answer so that it is disclosed rather than discovered.
Ask what the region requires of you. That is the tier, the sales conversation, the uplift, and the model versions the region supports [1][3]. Two of those four are costs you should be passing through to the client rather than absorbing.
Ask whether it can be changed later, and assume the answer is no [3]. Then write the whole thing into one file with the source URL and the date you checked it, because the only thing worse than not knowing is a confident answer that was true 14 months ago.
What still goes wrong
None of this is verifiable by you. A region setting produces a different domain to call and a slightly larger invoice, and no way to confirm that a packet did not transit somewhere else on a bad afternoon. You are relying on a documented commercial promise, which is worth considerably more than a marketing claim and considerably less than proof.
Residency is also not immunity, and the sales framing tends to blur that. Pinning inference to Europe changes where the computation happens, not who you are contracting with, and the contract itself is still governed by Ireland or California depending on your address [4]. Region controls the bytes. It does not change the company, its home jurisdiction, or the law that company answers to. Clients occasionally hear “EU region” and understand “EU company”, so it is worth saying the difference out loud before they write it into their own compliance file.
Then there is drift. Anthropic’s only workspace geo is "us" today [3], OpenAI’s list runs to 10 regions with 3 doing processing today [1], and the uplift is 10 percent for models released on or after a specific date in 2026 [1]. All three of those sentences are dated by construction. Regions get added, uplifts get repriced, country lists change with export policy, and none of it generates an email to you. Diary 20 minutes once a quarter to re-read the same four pages, and do it immediately the week any vendor writes to you about updated terms, because that message is the only warning you are going to get.
- 01OpenAI — Your data (data residency, retention, ZDR)developers.openai.com
- 02OpenAI — Supported countries and territoriesdevelopers.openai.com
- 03Anthropic — Data residencyplatform.claude.com
- 04Anthropic — Commercial Terms of Serviceanthropic.com
- 05Google — Gemini API Additional Terms of Serviceai.google.dev
- 06Microsoft — Deployment types in Microsoft Foundrylearn.microsoft.com
- 07Interim Measures for the Management of Generative AI Services (English translation of the PRC measures)chinalawtranslate.com
- 08Apple — Apple Intelligenceapple.com