3.2 AI for Defence · Module 3 · Data Sovereignty & Approved Providers

Where the Models Actually Process Data

Consumer vs enterprise, in-country processing, and the ‘residency is not sovereignty’ trap.

Sovereignty~18 min

The big idea

The same brand can be safe or unsafe depending on the tier. Consumer ChatGPT/Claude/Gemini may train on your input and retain it indefinitely; enterprise tiers contractually don't train, let you control retention, and add audit logging. Several providers now offer in-country processing in Australia — but ‘data residency’ is not full sovereignty: US-headquartered providers remain exposed to the US CLOUD Act, and a 2025 court order requires OpenAI to retain output logs (except for Zero-Data-Retention API customers).

Key insight: Data residency (where data sits) is not the same as sovereignty (whose laws reach it). A US-headquartered provider can store data in Australia and still be subject to US legal process.

What you'll see

How the major models handle data, and the consumer-vs-enterprise delta.

How the major tiers compare

The data-handling picture. Tap to expand.

Key points to remember

Tier matters more than brand: consumer trains/retains; enterprise doesn't.
Several providers offer in-country (Australian) processing now.
Residency ≠ sovereignty — CLOUD Act exposure remains for US providers.
Sovereign options exist (Vault Cloud, AUCloud, archTIS Kojensi, etc.) for higher needs.