Which country owns each major AI model, and how safe each one is for business use.
If your company is choosing an AI model, the vendor's home country decides who can legally reach your business data. Search any model below to see its home country, developer, open or closed weights, and a business safety score — then read how the score works further down. For deeper context, see our self-hosted AI models guide and AI tool comparisons.
77 models
🇺🇸 United StatesClosed
Nova (2)
Amazon · Public — Amazon (NASDAQ: AMZN)
95/100Low risk
Proprietary API (Amazon Bedrock) · Hosted only
Runs inside AWS via Bedrock/PrivateLink; not used for training. SOC 2, broad ISO suite, HIPAA-eligible, FedRAMP High, AWS Region data residency.
Anthropic · Private PBC (Long-Term Benefit Trust); Amazon and Google are major investors
91/100Low risk
Proprietary API · Hosted only
API/commercial data not used for training; available via AWS Bedrock and Google Vertex for regional routing. SOC 2, ISO 27001/42001, HIPAA BAA, zero-retention available.
Google (DeepMind) · Public — Alphabet Inc. (NASDAQ: GOOGL)
91/100Low risk
Proprietary API · Hosted only
Via Vertex AI, data is processed in your chosen Google Cloud region and not used for training; SOC 2, ISO 27001, HIPAA-eligible, GDPR DPA. Consumer Gemini app data can be used.
US enterprise vendor with strong SOC2/ISO/HIPAA posture and watsonx VPC/on-prem deployment. Apache-2.0 open weights plus a no-train enterprise contract make this low-risk for regulated buyers.
US enterprise platform vendor with strong compliance (SOC2/ISO/FedRAMP) and in-platform/VPC deployment. Apriel ships MIT open weights, so it is both contractually no-train and self-hostable.
US enterprise platform with strong compliance (SOC2/HIPAA) and VPC/in-account deployment via Mosaic AI. DBRX open weights plus no-train enterprise terms make it low-risk for regulated workloads.
OpenAI · Private PBC; Microsoft is the largest outside shareholder
84/100Low risk
Proprietary API · Hosted only
API and enterprise data are not used for training; consumer chats can be. Subject to US legal process (CLOUD Act). HIPAA BAA and zero-retention available.
OpenAI · Private PBC; Microsoft is the largest outside shareholder
84/100Low risk
Proprietary API · Hosted only
Announced June 26, 2026 as three tiers — Sol ($5/$30 per M tokens), Terra ($2.50/$15) and Luna ($1/$6). At launch it is a limited preview to a small set of vetted organizations via API and Codex, opened this way at the US government's request; general availability is planned "in the coming weeks." Compliance inherits OpenAI's platform (SOC 2, ISO 27001, HIPAA BAA on the API/Enterprise) once a model is in scope — confirm BAA coverage before sending regulated data during preview.
Anthropic · Private PBC (Long-Term Benefit Trust); Amazon and Google are major investors
84/100Low risk
Proprietary API · Hosted only
Anthropic's most capable public model (released June 9, 2026; $10/$50 per M input/output tokens), made safe for general use by safeguards that fall back to Opus 4.8 on high-risk cyber/bio requests — Anthropic reports 95%+ of sessions never fall back. US export controls suspended it June 12; the Commerce Department cleared it and it returned to GA globally July 1, 2026 on the Claude Platform, Claude.ai, Claude Code, and Cowork, with AWS Bedrock, Google Cloud, and Microsoft Foundry re-enabling in stages. As a "Mythos-class" model it carries a mandatory 30-day safety retention on business accounts (data used only for safety, then deleted), so full zero-retention is not available. Inherits Anthropic's SOC 2, ISO 27001, and ISO 42001; HIPAA BAA on the API/Enterprise.
Cohere · Private; merging with Aleph Alpha (announced 2026)
83/100Low risk
CC-BY-NC weights (non-commercial); commercial via API/VPC · Hosted only
Built for enterprise: SOC 2 Type II, ISO 27001/42001, private/VPC deployment with no Cohere data access; trains by default with opt-out and 30-day deletion.
Mistral AI · Private; investors include ASML, Nvidia, a16z
81/100Low risk
Apache 2.0 (open models); proprietary API (flagship) · Self-hostable
EU-native (GDPR) with EU data residency and zero-retention available; trains on inputs by default unless you opt out / enable ZDR. Open models are self-hostable.
US enterprise platform with SOC2/HIPAA and a contractual no-train enterprise tier plus VPC/self-managed deployment. Closed weights, so you rely on the contract rather than self-hosting.
Prime Intellect · Private; decentralized-training lab
78/100Moderate risk
MIT / Apache 2.0 · Self-hostable
US (San Francisco) lab that open-sources the full recipe — weights, datasets, RL environments and evals — under MIT/Apache. Fully self-hostable, so hosted-API exposure is avoidable.
Ai2 (Allen Institute for AI) · Nonprofit research institute
78/100Moderate risk
Apache 2.0 · Self-hostable
US nonprofit shipping fully open models — weights, training data and code all released. Maximum transparency and self-hostable, so there is effectively no hosted-data exposure.
Anthropic · Private PBC (Long-Term Benefit Trust); Amazon and Google are major investors
77/100Moderate risk
Proprietary API · Hosted only
NOT generally available. Same underlying model as Fable 5 but with safeguards lifted for authorized users; restricted to vetted cyber-defense and infrastructure partners under Project Glasswing, with a planned expansion to biomedical researchers. It is a frontier offensive-security-capable model — not a tool a typical business can deploy. US organizations' access was restored June 26, 2026 after government approval. Business accounts carry a mandatory 30-day safety retention. Because it ships through a restricted trusted-access program rather than the standard GA Enterprise surface, treat its compliance posture as program-specific — the usual Enterprise BAA/zero-retention terms do not automatically apply.
Open (weights, code, benchmarks released) · Self-hostable
Israel (Jerusalem) lab; LTX-2 video model was open-sourced in early 2026 with weights, code and benchmarks released. Self-hostable open weights remove hosted-data exposure; Israel is a moderate, Western-aligned jurisdiction.
US enterprise vendor with strong compliance; Firefly is marketed as commercially safe (licensed training data) and Adobe states it does not train on enterprise customer content. Closed weights, hosted only.
US (San Francisco) lab explicitly building US-made open-weight models. Apache-2.0 weights on Hugging Face are fully self-hostable, eliminating hosted-data exposure.
Inflection AI · Private; pivoted to enterprise after Microsoft team move
71/100Moderate risk
Proprietary · Hosted only
US enterprise AI vendor offering closed models with VPC/on-prem options and no-train enterprise terms. No open weights, so you depend on the contract rather than self-hosting.
US (San Francisco) image lab. Krea 2 Raw/Turbo ship as open weights under a custom license (self-hostable), while the broader hosted suite aggregates third-party models.
US (San Francisco) lab; Mochi 1 video weights are released under Apache 2.0 and self-hostable, which removes hosted-API data exposure for the open model.
xAI · Private; founded by Elon Musk; merged with X Corp.
70/100Moderate risk
Proprietary API · Hosted only
API data not used for training; SOC 2 Type 2 and zero-retention confirmed, but ISO 27001 and HIPAA BAA are not advertised. Tight X-platform integration is an added consideration.
Reka AI · Private; founded by ex-DeepMind/FAIR researchers
66/100Moderate risk
Apache 2.0 (some) / proprietary · Self-hostable
US-based multimodal lab; Flash-class weights are downloadable and on-prem/on-device deployable, while Nexus is offered as a hosted product. Low jurisdiction risk for a US business.
US-headquartered (San Francisco) agentic-coding lab; the smaller XS.2 ships as Apache-2.0 open weights while the flagship M.1 stays proprietary. Paris/London are satellite offices, not the legal HQ.
US search-augmented model offered API-only. Enterprise/API tier states it does not train on submitted data, but there are no open weights to self-host.
Rhymes AI · Private; founded by ex-Google AI researchers
64/100Elevated risk
Apache 2.0 · Self-hostable
Japan (Tokyo) lab; Aria is an open-weight multimodal MoE model under Apache 2.0. Self-hostable weights remove hosted-data exposure, and Japan is a moderate, Western-aligned jurisdiction.
G42 (Inception) · Private holding company; chaired by UAE ruling family
62/100Elevated risk
Apache 2.0 · Self-hostable
UAE (Abu Dhabi) state-linked group; Jais Arabic-focused models ship as open weights and are self-hostable, which removes hosted-data exposure. UAE is a moderate jurisdiction, though G42 has drawn US scrutiny over prior China ties.
US (New York) video lab; closed hosted models. Enterprise terms exist but consumer-tier training/retention is not clearly no-train, so treat as unknown for sensitive content.
Alibaba · Public — subsidiary of Alibaba Group (NYSE: BABA)
54/100Elevated risk
Apache 2.0 (open variants); proprietary API (Max) · Self-hostable
Open Qwen variants are Apache 2.0 and self-hostable (avoids China jurisdiction); the Qwen-Max flagship is API-only via Alibaba Cloud and processes data under PRC law.
China (Shanghai) lab; Step 3.x ships Apache-2.0 open weights. The hosted API stores data under PRC law, but self-hosting the open weights outside China removes the jurisdiction exposure.
Shanghai AI Laboratory · State-backed research laboratory
54/100Elevated risk
Apache 2.0 · Self-hostable
State-backed Chinese lab releasing Apache-2.0 open weights (Intern-S scientific/multimodal series). Self-hosting outside China removes the PRC-jurisdiction data exposure, though provenance remains a Chinese state-affiliated lab.
Beijing-listed company; Skywork/SkyReels open-source many releases under permissive licenses while the Tiangong app stays hosted. Hosted use falls under PRC law; self-hosting the open weights outside China mitigates the jurisdiction risk.
Thinking Machines Lab · Private; founded by ex-OpenAI leadership
53/100Elevated risk
Proprietary · Hosted only
US lab (Mira Murati). Tinker is a hosted fine-tuning API, not open weights; data-handling terms are still maturing, so treat training/retention as unknown.
US lab known for ultra-long-context (LTM-2) coding models, offered as a hosted product. No open weights and limited public data-handling detail, so retention/training is unknown.
US lab shipping the first commercial-scale diffusion LLM via an OpenAI-compatible API. Closed weights and early-stage compliance, so data-handling terms are still unknown.
US (San Francisco) spatial-intelligence lab; Marble is a hosted world-model product (text/image to 3D) with no open weights. Data-handling terms are still early, so training/retention is unknown.
US (San Francisco) video lab; closed, hosted-only. Public data-handling terms are limited, so training/retention should be treated as unknown for confidential inputs.
DeepSeek · Private; spun out of quant fund High-Flyer
52/100Elevated risk
MIT · Self-hostable
Hosted API stores data in the PRC under PRC law and trains on inputs — Elevated risk. MIT open weights, so self-hosting outside China removes the jurisdiction exposure entirely.
Israel (Tel Aviv) real-time generative lab; Oasis weights have been released while Mirage/MirageLSD run as a hosted livestream model. Israel is a moderate, Western-aligned jurisdiction; the open Oasis weights are self-hostable.
US image lab; closed, hosted-only service. By default it trains on user content and outputs are broadly licensed under its ToS, so do not submit confidential material.
US (Palo Alto) consumer-focused video app; closed and hosted-only, and its ToS broadly permits use of uploaded content to improve the service. Not suitable for confidential material.
Australia (Sydney) image lab, owned by Canva; closed, hosted-only. Data falls under Australian privacy law — a moderate, Western regime — but there are no open weights to self-host.
Ideogram · Private; founded by ex-Google Imagen researchers
46/100High risk
Proprietary · Hosted only
Headquartered in Toronto, Canada (not the US) — so data is processed under Canadian (PIPEDA) jurisdiction, a moderate but Western, treaty-aligned legal regime. Closed hosted model with no open weights.
Recraft · Private; UK-registered (Recraft AI Limited)
46/100High risk
Proprietary · Hosted only
UK (London) design-focused image lab; closed, hosted-only. Data is processed under UK GDPR — a moderate, Western legal regime — but there are no open weights to self-host.
Spain (Málaga) creative-AI platform; Mystic is a hosted image model. Data falls under EU GDPR — a moderate, Western regime — but there are no open weights to self-host.
Russia (Moscow), built by state-controlled Sberbank, a sanctioned entity. Some GigaChat models are MIT open-weight, but the hosted API stores data in Russia under Russian law and sanctions make any engagement high-risk for a US business.
Russia (Moscow); the flagship 5.1 Pro is hosted-only while a 5 Lite 8B variant is open-weight on Hugging Face. Hosted data is processed in Russia under Russian law, and Russia sanctions make engagement high-risk for US businesses.
Proprietary (specialized variants Apache 2.0) · Hosted only
Partially state-owned Chinese vendor; the flagship Spark X1 is a closed, hosted model trained on domestic compute. Hosted data falls under PRC law, and the model is on US export/entity-list scrutiny — high risk for Western data.
Chinese vendor on the US sanctions/entity list. Flagship SenseNova is closed and hosted under PRC law, though some U1 multimodal variants are open-weight and self-hostable. High risk for a US business given sanctions exposure.
Beijing-based Kuaishou; Kling is a closed, hosted-only video model. Uploaded content is processed in the PRC under PRC law and can be used to improve the service, with no self-hosting option — high risk for sensitive material.
Most leading AI models come from the United States or China, with a smaller cluster in Europe. Here is where the companies behind the best-known models are headquartered.
American AI models: ChatGPT and GPT-5 (OpenAI), Claude (Anthropic), Gemini and Gemma (Google), Llama (Meta), Phi (Microsoft), Grok (xAI), and Nova (Amazon) are all based in the United States.
Chinese AI models: DeepSeek, Qwen (Alibaba), ERNIE (Baidu), GLM (Z.ai), Kimi (Moonshot), Hunyuan (Tencent), Doubao (ByteDance), MiniMax, and Yi (01.AI) are based in China.
European AI models: Mistral is based in France; Aleph Alpha (Pharia) and Black Forest Labs (FLUX) are in Germany; and Stability AI is in the United Kingdom.
Other regions: Cohere is Canadian, AI21 (Jamba) is Israeli, Falcon (TII) is from the UAE, SEA-LION is from Singapore, Sarvam and Krutrim are Indian, HyperCLOVA X, EXAONE, and Solar are South Korean, and Sakana AI and NTT (tsuzumi) are Japanese.
Why Country of Origin Matters for Business
The country that controls an AI vendor controls the legal reach over your company data. A China-hosted API processes your prompts under PRC laws such as the National Intelligence Law. US vendors fall under the CLOUD Act, and EU vendors under GDPR. For regulated or sensitive business data, that jurisdiction is often the deciding factor.
Open weights change the math. When a model is open and your team self-hosts it, your data never leaves your infrastructure, so the vendor's home country stops mattering for privacy. This is why a self-hosted Chinese open-weight model can be safer than a closed US API for sensitive workloads. The deployment, not just the flag, drives the real risk.
In practice, the blocker we see stall AI projects is rarely the model's quality. It is a procurement or compliance team asking where the data goes and which law applies. This page is built to answer that question first.
How the Business Safety Score Works
Each model gets a score from 0 to 100, where higher means lower risk for a business handling real customer or company data. The score is computed the same way for every model from five equally weighted dimensions, so it is reproducible rather than an opinion.
Dimension (0–20 each)
What it measures for your business
Jurisdiction & data access
Home-country rule of law and government data-access regime for the hosted API.
Data privacy / training default
Whether the provider trains on your inputs, and if zero-retention is available.
Compliance certifications
SOC 2, ISO 27001, HIPAA BAA, and GDPR DPA availability.
Deployment control
Open weights (self-host) vs private/VPC vs API-only.
Transparency & accountability
Clear terms, vendor maturity, and security track record.
80–100 — Low risk: safe default for most business data.
65–79 — Moderate risk: fine with standard controls and review.
50–64 — Elevated risk: use with care; prefer self-hosting where open.
Below 50 — High risk: avoid for sensitive business data without legal review.
Scores reflect the typical hosted-API deployment most businesses use. For open-weight models, the note on each card explains how self-hosting lowers the real risk. Where a fact could not be confirmed from a primary source, the dimension is scored conservatively as unknown rather than guessed.
Researched and reviewed by Jonathan West, Founder of Layer3Labs, using each vendor's own privacy policies, trust centers, and license terms. Last updated July 2026; the AI landscape moves fast, so verify current terms before a final decision. Learn more about our team and approach.
Frequently Asked Questions
Where is OpenAI based?
OpenAI, the company behind ChatGPT and GPT-5, is based in San Francisco, California, in the United States. As a US company, its API and enterprise data are subject to US law.
Is ChatGPT American?
Yes. ChatGPT is made by OpenAI, an American company headquartered in San Francisco. Business data sent to the ChatGPT or GPT API is processed under US jurisdiction.
Is DeepSeek Chinese?
Yes. DeepSeek is a Chinese AI company based in Hangzhou, China. Its hosted API stores data in China under PRC law, but its open weights are MIT-licensed and can be self-hosted outside China.
Where is Mistral AI based?
Mistral AI is based in Paris, France. As an EU company it operates under GDPR, with EU data residency and zero-retention options available for business customers.
Where is Anthropic (Claude) based?
Anthropic, the maker of Claude, is based in San Francisco, California, in the United States. Claude’s API and enterprise data are not used for training and fall under US jurisdiction.
Which AI models are Chinese?
The major Chinese AI models are DeepSeek, Qwen (Alibaba), ERNIE (Baidu), GLM (Z.ai/Zhipu), Kimi (Moonshot), Hunyuan (Tencent), Doubao (ByteDance), MiniMax, and Yi (01.AI). Most are open-weight, which matters for business: the data-jurisdiction risk applies to their China-hosted APIs, not to the weights you download and self-host.
Are Chinese AI models safe for business?
It depends entirely on how your business deploys them. Using a China-hosted API means your company prompts are processed in the PRC under laws like the National Intelligence Law, which is an elevated risk for business data. Because most Chinese models are open-weight, self-hosting them outside China removes that jurisdiction exposure.
Which AI models are safest for business use?
For business, the highest-scoring models are US and European ones with enterprise terms: no training on your inputs, SOC 2 / ISO certifications, and VPC or self-hosting options. Microsoft Phi, Amazon Nova, Anthropic Claude, Google Gemini, and Meta Llama all score in the low-risk tier on our rubric.
How is the business safety score calculated?
Each model is scored from 0 to 100 across five equally weighted dimensions: legal jurisdiction and government data-access risk, data-privacy and training-default policy, compliance certifications, deployment control, and vendor transparency. Scores are computed the same way for every model, not assigned by hand.
Does an open-weight model remove data-privacy risk for a company?
Largely, yes. When your company self-hosts open weights on its own infrastructure, no prompts leave your environment and the vendor has no visibility into your data, regardless of where the company is based. Your team then owns its own security and compliance controls.
The Bottom Line
For business use, an AI model's country and deployment matter as much as its quality. US and European models with no-train terms and strong certifications score safest, China-hosted APIs carry the most jurisdiction risk, and open weights let you self-host to neutralize that risk entirely. Use the score as a starting filter, then confirm current terms with the vendor before you commit.
The right model depends on your data sensitivity, budget, and compliance needs. Book a free AI workflow audit and we will recommend the safest model that fits your use case — and wire it into your tools.