Blog/Governance/Checklist

Mapping your AI processors: a per-path checklist

1 September 2026Companion checklistObstruo team
Your AI runs on Azure, AWS or GCP. That does not tell you who processes the data.

Companion to "Your AI runs on Azure, AWS or GCP". Engineering guidance, not legal advice.

0 / 25

The register that lists your cloud provider is not wrong, it is just answering a different question. This checklist works the other way round: start from each path a request can take, and establish who is actually in it. Run it per path, not per vendor, and run it again whenever a model, provider, hosting mode or route changes.

1. Enumerate the paths, not the vendors

A single approved vendor can host several data paths with different properties. List the paths first.

2. Establish who is in the data flow

For each path, the model's publisher is not the answer. Confirm the actual parties.

3. Pin down retention and residency

Residency and retention are per-endpoint and per-model settings, not properties of the cloud account.

4. Account for abuse monitoring and human review

Safety systems can move content to a party that never appears in the main data path.

5. Follow the tools, agents and the dynamic graph

Once an agent invokes tools, the processing chain stops being a single call.

6. Turn the answers into evidence, then keep them current

A one-time map ages the moment the architecture changes.