Companion to "Your AI runs on Azure, AWS or GCP". Engineering guidance, not legal advice.
0 / 25
The register that lists your cloud provider is not wrong, it is just answering a different question. This checklist works the other way round: start from each path a request can take, and establish who is actually in it. Run it per path, not per vendor, and run it again whenever a model, provider, hosting mode or route changes.
1. Enumerate the paths, not the vendors
A single approved vendor can host several data paths with different properties. List the paths first.
2. Establish who is in the data flow
For each path, the model's publisher is not the answer. Confirm the actual parties.
3. Pin down retention and residency
Residency and retention are per-endpoint and per-model settings, not properties of the cloud account.
4. Account for abuse monitoring and human review
Safety systems can move content to a party that never appears in the main data path.
5. Follow the tools, agents and the dynamic graph
Once an agent invokes tools, the processing chain stops being a single call.
6. Turn the answers into evidence, then keep them current
A one-time map ages the moment the architecture changes.