Wayfinder: Claude and GPT and Data Bridges Copy

This is the third article of six. In part 1, I explained what a data processing agreement is and why Icelandic business needs to watch carefully for changes to them.

The Broken Promise, part 3.

Andri Örvar Baldvinsson

Articles

Here I'm pulling together the big picture: how the same models can end up in very different places depending on the path you choose using our interactive guide.

Over recent months, we've seen deals between cloud providers and model makers stacking up one after another, and they can affect where your data ends up. What confuses some people is that Anthropic and OpenAI are both present inside cloud provider environments and also offer their own API services directly or through subscriptions with their own clients.

There are thirteen possible paths available today, and the list isn't even complete — new deals get added and things change fast. Rather than listing them all here, I'll show you three examples that cover the spectrum, and further down in this article there's an interactive guide where you can find your exact path. The core point is this: the same models follow very different processing agreements depending on how you connect them to your business.

Three examples using the same models

Amazon Bedrock (Claude on AWS)  within EU Data Boundary. When you call Claude through Amazon Bedrock, the model runs inside AWS in the region you choose (like Frankfurt or Stockholm). Your data follows a processing agreement with AWS (AWS DPA under European jurisdiction). Anthropic doesn't see your data in this setup, and it never leaves the AWS environment.

Microsoft 365 Copilot  both inside and outside. Here, both OpenAI and Anthropic are subprocessors for Microsoft on different parts of the experience. Copilot stays within the EU data boundary for OpenAI models (on EU/EFTA tenants), but goes outside it (to the US) in cases where Claude handles the task. The system picks the model based on the job, so the same product can be both inside and outside the data boundary depending on what happens. The agreement falls under Microsoft's DPA.

ChatGPT Plus / Free outside, and shared for training. Individual subscriptions (chatgpt.com and mobile app). No European hosting option available, and your data is in the US. What's more, your data is used for training by default unless you turn it off manually. This is the package most employees use personally, which means work data can flow into OpenAI's training process without your company knowing.

Find your path

Instead of reading through all thirteen paths, you can answer three simple questions below — which model you use, how you access it, through which path, and see right away whether it keeps your data within EU Data Boundary, who the processor is, and what jurisdiction it falls under:

Hvar lenda gögnin þín?

Svaraðu þremur spurningum og sjáðu hvort þín leið heldur gögnunum innan EU Data Boundary.

1Hvaða módel ert þú að nota eða langar að nota í vinnunni?

If you'd rather see all thirteen paths side by side, the full table is in sections 1 and 2, where you can filter it by model, processor, EU Data Boundary, and jurisdiction.

Are there exceptions to keeping processing within Europe?

The short answer is yes. All cloud providers offer setups where data can go outside, and the difference is in what the default is and how aware you are of the choice.

AWS Bedrock offers a feature called Cross-Region Inference as an optional setting (opt-in). If you choose a specific regional endpoint (like Frankfurt), processing stays right there. You can also pick a geographic endpoint ("EU") that spreads the load across European regions (Frankfurt, Stockholm, Ireland, Paris) while keeping data within Europe. Finally, you can choose a global endpoint that can send requests anywhere in the world, but you're making that choice yourself.

Vertex AI from Google uses a similar setup with regional, multi-region, and global endpoints. The multi-region endpoint spreads load within the EU or US, the regional one stays in one place, and the global one can go anywhere — and again, you're choosing this yourself.

Microsoft 365 Copilot instead uses a feature called Flex Routing, which has been turned on by default for new tenants since March 2026. You can turn it off, but the default setting allows OpenAI processing to move outside the EU when load is high (Claude processing goes outside European data boundaries anyway, as we mentioned earlier).

The difference in one sentence: With Bedrock and Vertex you have to choose to go outside your region, but with Microsoft you have to choose not to.

A good question to ask your service provider:

What kind of endpoints are we using in the cloud today, and what exactly happens to my data when the cloud provider's load increases — could it go anywhere?

💡 Lost in the terminology?

If you want to understand more about all these new names, abbreviations, and technical terms in AI (like MCP, RAG, and more), I recommend checking out the article: Can I offer you some scrambled data porridge?

Data bridges that get forgotten 

This is actually such a big topic it deserves its own article, but I want to slip this in as a small "food for thought" for those who work in the field. It's not enough that the model itself is secure within Europe if the "data bridge" feeding it leaks.

More and more companies are connecting AI directly to their internal systems (business systems, document storage, or custom software) through APIs or MCP services (Model Context Protocol).

The technical risk: If this connection or the data bridge itself runs on a US-based server, the request goes there to fetch data before the European AI gets to answer. At that point, the protection you thought you had is broken, and not by the AI itself, but because of how the tech was set up — something that might not have been reviewed carefully enough.

Changes to processing agreements in other systems: The flip side of the coin involves the systems you're connecting AI to. Think of giants like Atlassian (Jira and Confluence) that many Icelandic companies use on infrastructure within Europe. In August 2026, new terms take effect (Data Contribution Policy) where Atlassian starts using customer data by default to train their AI models.

What changes the game here is that if your company is on Free, Standard, or Premium subscriptions, metadata collection — like employee search terms, task structure, and information in Confluence — is used for training. These are often incredibly valuable data, and it's easy to see how this insight gives Atlassian a unique window into workflows and processes that no one else should have access to, and only those paying for the most expensive Enterprise licenses have any say in the matter.

This rule applies to all data: it's not just about where the model sits, but where requests go, how they travel (MCP/API), and what terms apply to the systems they touch.

What's next?

In sections 1 through 3, we've covered how cloud providers work today, where European data boundaries hold and where they don't, and why the same models (Claude and GPT) can behave differently depending on which path you choose. Today it's not enough to pick the right cloud provider or the right model maker — you also have to pick the right path within it.

In section 4, I'll dig into the consequences: why this isn't just a technical problem but a business decision the buyer needs to own. We'll look at how one small settings tweak can move your data from Frankfurt to Virginia with no fuss, and what your service provider's responsibility is in this process.

In section 5, I cover data that leaks through code in software development, and in section 6 we'll review choosing between different models and what key points to keep in mind when making implementation decisions.


Contact us