By Jonathan West · Updated July 1, 2026

AI Models by Country & Business Safety

Which country owns each major AI model, and how safe each one is for business use.

If your company is choosing an AI model, the vendor's home country decides who can legally reach your business data. Search any model below to see its home country, developer, open or closed weights, and a business safety score — then read how the score works further down. For deeper context, see our self-hosted AI models guide and AI tool comparisons.

77 models

🇺🇸 United StatesClosed

Nova (2)

Amazon · Public — Amazon (NASDAQ: AMZN)
95/100Low risk
Proprietary API (Amazon Bedrock) · Hosted only

Runs inside AWS via Bedrock/PrivateLink; not used for training. SOC 2, broad ISO suite, HIPAA-eligible, FedRAMP High, AWS Region data residency.

🇺🇸 United StatesOpen

Phi-4

Microsoft · Public — Microsoft (NASDAQ: MSFT)
93/100Low risk
MIT · Self-hostable

Permissive MIT open weights; self-host anywhere, or run on Azure with SOC 2 / ISO 27001 / HIPAA BAA.

🇩🇪 GermanyOpen

Pharia-1

Aleph Alpha · Private; Schwarz Group >20%; merging with Cohere (2026)
93/100Low risk
Open Aleph License (non-commercial) · Self-hostable

Built explicitly for GDPR / EU AI Act with on-prem/sovereign deployment; no prompt storage on the public API. Weights are non-commercial.

🇺🇸 United StatesClosed

Claude (Opus / Sonnet / Haiku)

Anthropic · Private PBC (Long-Term Benefit Trust); Amazon and Google are major investors
91/100Low risk
Proprietary API · Hosted only

API/commercial data not used for training; available via AWS Bedrock and Google Vertex for regional routing. SOC 2, ISO 27001/42001, HIPAA BAA, zero-retention available.

🇺🇸 United StatesClosed

Gemini (2.x Pro / Flash)

Google (DeepMind) · Public — Alphabet Inc. (NASDAQ: GOOGL)
91/100Low risk
Proprietary API · Hosted only

Via Vertex AI, data is processed in your chosen Google Cloud region and not used for training; SOC 2, ISO 27001, HIPAA-eligible, GDPR DPA. Consumer Gemini app data can be used.

🇺🇸 United StatesOpen

gpt-oss (120b / 20b)

OpenAI · Private PBC; Microsoft is the largest outside shareholder
88/100Low risk
Apache 2.0 · Self-hostable

Open weights you can self-host; data stays in your own infrastructure and OpenAI has no visibility into inputs.

🇺🇸 United StatesOpen

Gemma (3 / 4)

Google (DeepMind) · Public — Alphabet Inc. (NASDAQ: GOOGL)
88/100Low risk
Gemma Terms of Use (open weights, use restrictions) · Self-hostable

Open weights for self-hosting; the Gemma Terms of Use impose contractual use restrictions even when self-hosted.

🇺🇸 United StatesOpen

Llama (3.x / 4)

Meta · Public — Meta Platforms (NASDAQ: META)
88/100Low risk
Llama Community License (source-available, >700M MAU restriction) · Self-hostable

Open weights you fully self-host; license governed by California law and caps very large commercial deployments.

🇺🇸 United StatesOpen

Granite (4.x)

IBM · Public (NYSE: IBM)
88/100Low risk
Apache 2.0 · Self-hostable

US enterprise vendor with strong SOC2/ISO/HIPAA posture and watsonx VPC/on-prem deployment. Apache-2.0 open weights plus a no-train enterprise contract make this low-risk for regulated buyers.

🇺🇸 United StatesOpen

Apriel (ServiceNow)

ServiceNow · Public (NYSE: NOW)
88/100Low risk
MIT · Self-hostable

US enterprise platform vendor with strong compliance (SOC2/ISO/FedRAMP) and in-platform/VPC deployment. Apriel ships MIT open weights, so it is both contractually no-train and self-hostable.

🇺🇸 United StatesOpen

DBRX

Databricks · Private; major data/AI platform
88/100Low risk
Databricks Open Model License · Self-hostable

US enterprise platform with strong compliance (SOC2/HIPAA) and VPC/in-account deployment via Mosaic AI. DBRX open weights plus no-train enterprise terms make it low-risk for regulated workloads.

🇮🇱 IsraelOpen

Jamba (1.x)

AI21 Labs · Private; investors include Google, Nvidia, Intel Capital
85/100Low risk
Jamba Open Model License · Hosted only

Israel-based (EU adequacy applies); SOC 2 and ISO 27001/27017/27018, with private VPC/on-prem deployment for regulated data.

🇺🇸 United StatesClosed

GPT-5 (and GPT-4o, o-series)

OpenAI · Private PBC; Microsoft is the largest outside shareholder
84/100Low risk
Proprietary API · Hosted only

API and enterprise data are not used for training; consumer chats can be. Subject to US legal process (CLOUD Act). HIPAA BAA and zero-retention available.

🇺🇸 United StatesClosed

GPT-5.6 (Sol / Terra / Luna)

OpenAI · Private PBC; Microsoft is the largest outside shareholder
84/100Low risk
Proprietary API · Hosted only

Announced June 26, 2026 as three tiers — Sol ($5/$30 per M tokens), Terra ($2.50/$15) and Luna ($1/$6). At launch it is a limited preview to a small set of vetted organizations via API and Codex, opened this way at the US government's request; general availability is planned "in the coming weeks." Compliance inherits OpenAI's platform (SOC 2, ISO 27001, HIPAA BAA on the API/Enterprise) once a model is in scope — confirm BAA coverage before sending regulated data during preview.

🇺🇸 United StatesClosed

Claude Fable 5

Anthropic · Private PBC (Long-Term Benefit Trust); Amazon and Google are major investors
84/100Low risk
Proprietary API · Hosted only

Anthropic's most capable public model (released June 9, 2026; $10/$50 per M input/output tokens), made safe for general use by safeguards that fall back to Opus 4.8 on high-risk cyber/bio requests — Anthropic reports 95%+ of sessions never fall back. US export controls suspended it June 12; the Commerce Department cleared it and it returned to GA globally July 1, 2026 on the Claude Platform, Claude.ai, Claude Code, and Cowork, with AWS Bedrock, Google Cloud, and Microsoft Foundry re-enabling in stages. As a "Mythos-class" model it carries a mandatory 30-day safety retention on business accounts (data used only for safety, then deleted), so full zero-retention is not available. Inherits Anthropic's SOC 2, ISO 27001, and ISO 42001; HIPAA BAA on the API/Enterprise.

🇨🇦 CanadaMixed

Command (A / R+)

Cohere · Private; merging with Aleph Alpha (announced 2026)
83/100Low risk
CC-BY-NC weights (non-commercial); commercial via API/VPC · Hosted only

Built for enterprise: SOC 2 Type II, ISO 27001/42001, private/VPC deployment with no Cohere data access; trains by default with opt-out and 30-day deletion.

🇫🇷 FranceMixed

Mistral (Large / open models)

Mistral AI · Private; investors include ASML, Nvidia, a16z
81/100Low risk
Apache 2.0 (open models); proprietary API (flagship) · Self-hostable

EU-native (GDPR) with EU data residency and zero-retention available; trains on inputs by default unless you opt out / enable ZDR. Open models are self-hostable.

🇺🇸 United StatesClosed

Palmyra (X5)

Writer · Private; enterprise generative-AI vendor
78/100Moderate risk
Proprietary · Hosted only

US enterprise platform with SOC2/HIPAA and a contractual no-train enterprise tier plus VPC/self-managed deployment. Closed weights, so you rely on the contract rather than self-hosting.

🇺🇸 United StatesOpen

INTELLECT-3

Prime Intellect · Private; decentralized-training lab
78/100Moderate risk
MIT / Apache 2.0 · Self-hostable

US (San Francisco) lab that open-sources the full recipe — weights, datasets, RL environments and evals — under MIT/Apache. Fully self-hostable, so hosted-API exposure is avoidable.

🇺🇸 United StatesOpen

OLMo (3) / Molmo

Ai2 (Allen Institute for AI) · Nonprofit research institute
78/100Moderate risk
Apache 2.0 · Self-hostable

US nonprofit shipping fully open models — weights, training data and code all released. Maximum transparency and self-hostable, so there is effectively no hosted-data exposure.

🇺🇸 United StatesOpen

Hermes (4)

Nous Research · Private; open-research collective
78/100Moderate risk
Apache 2.0 / Llama-derived · Self-hostable

US open-research group releasing weights plus extensive training detail. Self-hostable open weights mean no hosted-API jurisdiction exposure.

🇺🇸 United StatesClosed

Claude Mythos 5

Anthropic · Private PBC (Long-Term Benefit Trust); Amazon and Google are major investors
77/100Moderate risk
Proprietary API · Hosted only

NOT generally available. Same underlying model as Fable 5 but with safeguards lifted for authorized users; restricted to vetted cyber-defense and infrastructure partners under Project Glasswing, with a planned expansion to biomedical researchers. It is a frontier offensive-security-capable model — not a tool a typical business can deploy. US organizations' access was restored June 26, 2026 after government approval. Business accounts carry a mandatory 30-day safety retention. Because it ships through a restricted trusted-access program rather than the standard GA Enterprise surface, treat its compliance posture as program-specific — the usual Enterprise BAA/zero-retention terms do not automatically apply.

🇮🇱 IsraelOpen

LTX-2 (Lightricks)

Lightricks · Private; established app/AI company
76/100Moderate risk
Open (weights, code, benchmarks released) · Self-hostable

Israel (Jerusalem) lab; LTX-2 video model was open-sourced in early 2026 with weights, code and benchmarks released. Self-hostable open weights remove hosted-data exposure; Israel is a moderate, Western-aligned jurisdiction.

🇺🇸 United StatesClosed

Firefly Image (5)

Adobe · Public (NASDAQ: ADBE)
75/100Moderate risk
Proprietary · Hosted only

US enterprise vendor with strong compliance; Firefly is marketed as commercially safe (licensed training data) and Adobe states it does not train on enterprise customer content. Closed weights, hosted only.

🇺🇸 United StatesOpen

Liquid AI (LFM2.5)

Liquid AI · Private; spun out of MIT CSAIL
71/100Moderate risk
LFM Open License (commercial use permitted) · Self-hostable

US (Boston) on-device foundation-model lab. Open weights run locally via llama.cpp/vLLM/MLX, so data never leaves your environment.

🇺🇸 United StatesOpen

Trinity (Large / Mini)

Arcee AI · Private; small US lab
71/100Moderate risk
Apache 2.0 · Self-hostable

US (San Francisco) lab explicitly building US-made open-weight models. Apache-2.0 weights on Hugging Face are fully self-hostable, eliminating hosted-data exposure.

🇺🇸 United StatesClosed

Inflection-3

Inflection AI · Private; pivoted to enterprise after Microsoft team move
71/100Moderate risk
Proprietary · Hosted only

US enterprise AI vendor offering closed models with VPC/on-prem options and no-train enterprise terms. No open weights, so you depend on the contract rather than self-hosting.

🇺🇸 United StatesMixed

Krea (2)

Krea · Private; generative creative platform
71/100Moderate risk
Custom open-weights license / proprietary · Self-hostable

US (San Francisco) image lab. Krea 2 Raw/Turbo ship as open weights under a custom license (self-hostable), while the broader hosted suite aggregates third-party models.

🇺🇸 United StatesOpen

Mochi (Genmo)

Genmo · Private; open video-model lab
71/100Moderate risk
Apache 2.0 · Self-hostable

US (San Francisco) lab; Mochi 1 video weights are released under Apache 2.0 and self-hostable, which removes hosted-API data exposure for the open model.

🇺🇸 United StatesClosed

Grok (4.x)

xAI · Private; founded by Elon Musk; merged with X Corp.
70/100Moderate risk
Proprietary API · Hosted only

API data not used for training; SOC 2 Type 2 and zero-retention confirmed, but ISO 27001 and HIPAA BAA are not advertised. Tight X-platform integration is an added consideration.

🇬🇧 United KingdomOpen

Stable Diffusion (image)

Stability AI · Private; investors include Coatue, Lightspeed, WPP
69/100Moderate risk
Stability Community License (free under $1M revenue) · Self-hostable

UK-based (UK GDPR); open weights run fully locally, so all data stays on your own hardware. Free for entities under $1M revenue.

🇩🇪 GermanyMixed

FLUX (image)

Black Forest Labs · Private; investors include Salesforce Ventures, a16z, Nvidia
69/100Moderate risk
Apache 2.0 (schnell); non-commercial (dev); closed (pro/max) · Self-hostable

German/EU (GDPR); schnell variant is Apache 2.0 and self-hostable, dev is non-commercial, and pro/max are API-only.

🇸🇬 SingaporeOpen

SEA-LION

AI Singapore · Government-backed national programme (hosted at NUS, NRF-supported)
69/100Moderate risk
MIT (current release) · Self-hostable

Singapore government-backed open model for Southeast Asian languages; weights are downloadable and self-hostable.

🇰🇷 South KoreaMixed

HyperCLOVA X

NAVER · Public — NAVER Corporation (KRX)
69/100Moderate risk
HyperCLOVA X SEED License (open) + closed commercial tier · Self-hostable

Korea’s sovereign Korean-language model; open SEED weights are self-hostable, with VPC deployment for the commercial tier via NAVER Cloud.

🇰🇷 South KoreaOpen

EXAONE

LG AI Research · Research arm of LG Corporation
69/100Moderate risk
EXAONE AI Model License (non-commercial) · Self-hostable

Korean/English open weights, but the license is non-commercial — commercial use requires a separate agreement with LG AI Research.

🇰🇷 South KoreaOpen

Solar

Upstage · Private startup
69/100Moderate risk
Apache 2.0 (smaller models); custom license (100B) · Self-hostable

Smaller Solar models are Apache 2.0 and self-hostable; the 100B flagship uses a custom weights license, with a hosted API also available.

🇯🇵 JapanMixed

Sakana models

Sakana AI · Private; investors include NTT
69/100Moderate risk
Apache 2.0 (research releases); proprietary (enterprise) · Self-hostable

Tokyo lab that open-sources research artifacts under Apache 2.0 while building proprietary models for Japanese enterprises.

🇺🇸 United StatesMixed

Reka (Nexus / Flash)

Reka AI · Private; founded by ex-DeepMind/FAIR researchers
66/100Moderate risk
Apache 2.0 (some) / proprietary · Self-hostable

US-based multimodal lab; Flash-class weights are downloadable and on-prem/on-device deployable, while Nexus is offered as a hosted product. Low jurisdiction risk for a US business.

🇺🇸 United StatesMixed

Laguna (M.1 / XS.2)

Poolside · Private; HQ San Francisco (offices in Paris/London)
66/100Moderate risk
Apache 2.0 (XS.2) / proprietary (M.1) · Self-hostable

US-headquartered (San Francisco) agentic-coding lab; the smaller XS.2 ships as Apache-2.0 open weights while the flagship M.1 stays proprietary. Paris/London are satellite offices, not the legal HQ.

🇮🇳 IndiaOpen

Sarvam

Sarvam AI · Private; selected by India’s IndiaAI Mission for a sovereign model
64/100Elevated risk
Apache 2.0 · Self-hostable

Positioned as India’s sovereign AI: built and operated in India with private/on-prem deployment and claimed SOC 2 / ISO 27001 / DPDP compliance.

🇯🇵 JapanClosed

tsuzumi

NTT · Public — Nippon Telegraph and Telephone (TSE)
64/100Elevated risk
Commercial / proprietary · Hosted only

NTT’s lightweight Japanese-specialized model, marketed for enterprise on-prem / private deployment.

🇺🇸 United StatesClosed

Sonar (Perplexity)

Perplexity · Private
64/100Elevated risk
Proprietary · Hosted only

US search-augmented model offered API-only. Enterprise/API tier states it does not train on submitted data, but there are no open weights to self-host.

🇺🇸 United StatesClosed

Devin / SWE-1.5 (Cognition)

Cognition · Private
64/100Elevated risk
Proprietary · Hosted only

US coding-agent lab. SWE-1.5 is delivered as a hosted product/API with no open weights; enterprise terms address no-train but you cannot self-host.

🇯🇵 JapanOpen

Aria (Rhymes AI)

Rhymes AI · Private; founded by ex-Google AI researchers
64/100Elevated risk
Apache 2.0 · Self-hostable

Japan (Tokyo) lab; Aria is an open-weight multimodal MoE model under Apache 2.0. Self-hostable weights remove hosted-data exposure, and Japan is a moderate, Western-aligned jurisdiction.

🇮🇳 IndiaOpen

Krutrim

Krutrim AI Labs (Ola) · Private; backed by Ola / Bhavish Aggarwal
62/100Elevated risk
Krutrim Community License · Self-hostable

India-built multilingual Indic model; open weights are self-hostable, also served via Krutrim Cloud.

🇦🇪 United Arab EmiratesOpen

Falcon

Technology Innovation Institute (TII) · Government-backed (Abu Dhabi ATRC)
62/100Elevated risk
TII Falcon License (Apache 2.0-based) · Self-hostable

Abu Dhabi government-backed open models for research and commercial use; weights are downloadable and self-hostable.

🇦🇪 United Arab EmiratesOpen

Jais (2)

G42 (Inception) · Private holding company; chaired by UAE ruling family
62/100Elevated risk
Apache 2.0 · Self-hostable

UAE (Abu Dhabi) state-linked group; Jais Arabic-focused models ship as open weights and are self-hostable, which removes hosted-data exposure. UAE is a moderate jurisdiction, though G42 has drawn US scrutiny over prior China ties.

🇺🇸 United StatesClosed

Gen-4.5 (Runway)

Runway · Private; generative video lab
58/100Elevated risk
Proprietary · Hosted only

US (New York) video lab; closed hosted models. Enterprise terms exist but consumer-tier training/retention is not clearly no-train, so treat as unknown for sensitive content.

🇨🇳 ChinaMixed

Qwen (3.x; Qwen-Max closed)

Alibaba · Public — subsidiary of Alibaba Group (NYSE: BABA)
54/100Elevated risk
Apache 2.0 (open variants); proprietary API (Max) · Self-hostable

Open Qwen variants are Apache 2.0 and self-hostable (avoids China jurisdiction); the Qwen-Max flagship is API-only via Alibaba Cloud and processes data under PRC law.

🇨🇳 ChinaOpen

ERNIE (4.5)

Baidu · Public — Baidu, Inc. (NASDAQ: BIDU)
54/100Elevated risk
Apache 2.0 (open release) · Self-hostable

ERNIE 4.5 open weights are Apache 2.0 and self-hostable; Baidu’s hosted API processes data in the PRC under PRC law.

🇨🇳 ChinaOpen

GLM (4.6 / 5)

Z.ai (Zhipu AI) · Public (listed in China); backed by Alibaba, Tencent
54/100Elevated risk
MIT · Self-hostable

MIT open weights — self-host to avoid China jurisdiction; the Z.ai hosted API routes data to PRC processing.

🇨🇳 ChinaOpen

Kimi (K2)

Moonshot AI · Private; backed by Alibaba, Tencent
54/100Elevated risk
Modified MIT (attribution above scale thresholds) · Self-hostable

Open weights you can self-host; the Moonshot hosted API processes data in the PRC under PRC law.

🇨🇳 ChinaOpen

Hunyuan

Tencent · Public — Tencent Holdings (HKEX: 0700)
54/100Elevated risk
Tencent Hunyuan Community License (excludes EU/UK/South Korea) · Self-hostable

Open weights, but the license explicitly bars use in the EU, UK, and South Korea; the hosted API processes data under PRC law.

🇨🇳 ChinaOpen

MiniMax (M2)

MiniMax · Public (HKEX-listed); backed by Alibaba, Tencent
54/100Elevated risk
MIT (M2/M2.5); restricted for newer M2.7 · Self-hostable

M2/M2.5 are MIT and self-hostable; the hosted API processes data under PRC law, and the newer M2.7 license restricts commercial use.

🇨🇳 ChinaOpen

Step (3.x)

StepFun (阶跃星辰) · Private; Shanghai lab, Tencent-backed
54/100Elevated risk
Apache 2.0 · Self-hostable

China (Shanghai) lab; Step 3.x ships Apache-2.0 open weights. The hosted API stores data under PRC law, but self-hosting the open weights outside China removes the jurisdiction exposure.

🇨🇳 ChinaOpen

InternLM / Intern-S (S1 / S2)

Shanghai AI Laboratory · State-backed research laboratory
54/100Elevated risk
Apache 2.0 · Self-hostable

State-backed Chinese lab releasing Apache-2.0 open weights (Intern-S scientific/multimodal series). Self-hosting outside China removes the PRC-jurisdiction data exposure, though provenance remains a Chinese state-affiliated lab.

🇨🇳 ChinaMixed

Tiangong / Skywork / SkyReels

Skywork · Kunlun (昆仑万维) · Public (SZSE: 300418)
54/100Elevated risk
Apache 2.0 (open releases) / proprietary · Self-hostable

Beijing-listed company; Skywork/SkyReels open-source many releases under permissive licenses while the Tiangong app stays hosted. Hosted use falls under PRC law; self-hosting the open weights outside China mitigates the jurisdiction risk.

🇺🇸 United StatesClosed

Tinker (Thinking Machines Lab)

Thinking Machines Lab · Private; founded by ex-OpenAI leadership
53/100Elevated risk
Proprietary · Hosted only

US lab (Mira Murati). Tinker is a hosted fine-tuning API, not open weights; data-handling terms are still maturing, so treat training/retention as unknown.

🇺🇸 United StatesClosed

LTM-2 (Magic.dev)

Magic.dev · Private
53/100Elevated risk
Proprietary · Hosted only

US lab known for ultra-long-context (LTM-2) coding models, offered as a hosted product. No open weights and limited public data-handling detail, so retention/training is unknown.

🇺🇸 United StatesClosed

Mercury (2)

Inception Labs · Private; diffusion-LLM lab
53/100Elevated risk
Proprietary · Hosted only

US lab shipping the first commercial-scale diffusion LLM via an OpenAI-compatible API. Closed weights and early-stage compliance, so data-handling terms are still unknown.

🇺🇸 United StatesClosed

Marble (World Labs)

World Labs · Private; founded by Fei-Fei Li
53/100Elevated risk
Proprietary · Hosted only

US (San Francisco) spatial-intelligence lab; Marble is a hosted world-model product (text/image to 3D) with no open weights. Data-handling terms are still early, so training/retention is unknown.

🇺🇸 United StatesClosed

Ray3 / Dream Machine (Luma AI)

Luma AI · Private; generative video/3D lab
53/100Elevated risk
Proprietary · Hosted only

US (San Francisco) video lab; closed, hosted-only. Public data-handling terms are limited, so training/retention should be treated as unknown for confidential inputs.

🇨🇳 ChinaOpen

DeepSeek (V4 / R1)

DeepSeek · Private; spun out of quant fund High-Flyer
52/100Elevated risk
MIT · Self-hostable

Hosted API stores data in the PRC under PRC law and trains on inputs — Elevated risk. MIT open weights, so self-hosting outside China removes the jurisdiction exposure entirely.

🇮🇱 IsraelMixed

Oasis / MirageLSD (Decart)

Decart · Private; Sequoia-backed
52/100Elevated risk
Open-weight (Oasis) / proprietary · Self-hostable

Israel (Tel Aviv) real-time generative lab; Oasis weights have been released while Mirage/MirageLSD run as a hosted livestream model. Israel is a moderate, Western-aligned jurisdiction; the open Oasis weights are self-hostable.

🇺🇸 United StatesClosed

Midjourney (V8.1 / Niji)

Midjourney · Private; independent research lab
51/100Elevated risk
Proprietary · Hosted only

US image lab; closed, hosted-only service. By default it trains on user content and outputs are broadly licensed under its ToS, so do not submit confidential material.

🇺🇸 United StatesClosed

Pika (2.5)

Pika · Private; consumer video lab
51/100Elevated risk
Proprietary · Hosted only

US (Palo Alto) consumer-focused video app; closed and hosted-only, and its ToS broadly permits use of uploaded content to improve the service. Not suitable for confidential material.

🇦🇺 AustraliaClosed

Lucid Origin (Leonardo.Ai)

Leonardo.Ai · Private; subsidiary of Canva
51/100Elevated risk
Proprietary · Hosted only

Australia (Sydney) image lab, owned by Canva; closed, hosted-only. Data falls under Australian privacy law — a moderate, Western regime — but there are no open weights to self-host.

🇨🇳 ChinaOpen

Yi (1.5)

01.AI · Private; founded by Kai-Fu Lee (line largely inactive since 2024)
48/100High risk
Apache 2.0 · Self-hostable

Apache 2.0 open weights are self-hostable; 01.AI has pivoted away from frontier pretraining, so the line is aging.

🇨🇦 CanadaClosed

Ideogram (4.0)

Ideogram · Private; founded by ex-Google Imagen researchers
46/100High risk
Proprietary · Hosted only

Headquartered in Toronto, Canada (not the US) — so data is processed under Canadian (PIPEDA) jurisdiction, a moderate but Western, treaty-aligned legal regime. Closed hosted model with no open weights.

🇬🇧 United KingdomClosed

Recraft (V4)

Recraft · Private; UK-registered (Recraft AI Limited)
46/100High risk
Proprietary · Hosted only

UK (London) design-focused image lab; closed, hosted-only. Data is processed under UK GDPR — a moderate, Western legal regime — but there are no open weights to self-host.

🇪🇸 SpainClosed

Mystic (Freepik / Magnific)

Magnific (formerly Freepik) · Private; bootstrapped/profitable
46/100High risk
Proprietary · Hosted only

Spain (Málaga) creative-AI platform; Mystic is a hosted image model. Data falls under EU GDPR — a moderate, Western regime — but there are no open weights to self-host.

🇷🇺 RussiaMixed

GigaChat (Ultra / Lightning)

Sber · State-controlled bank (Sberbank)
40/100High risk
MIT (open releases) / proprietary · Self-hostable

Russia (Moscow), built by state-controlled Sberbank, a sanctioned entity. Some GigaChat models are MIT open-weight, but the hosted API stores data in Russia under Russian law and sanctions make any engagement high-risk for a US business.

🇷🇺 RussiaMixed

YandexGPT (5 / 5.1)

Yandex · Public; Russian internet group
40/100High risk
Open-weight (5 Lite) / proprietary (Pro) · Self-hostable

Russia (Moscow); the flagship 5.1 Pro is hosted-only while a 5 Lite 8B variant is open-weight on Hugging Face. Hosted data is processed in Russia under Russian law, and Russia sanctions make engagement high-risk for US businesses.

🇨🇳 ChinaClosed

Doubao / Seed (flagship)

ByteDance · Private — subsidiary of ByteDance
38/100High risk
Proprietary API (Volcano Engine) · Hosted only

Flagship Doubao is API-only via Volcano Engine and cannot be removed from the China-jurisdiction path; only smaller Seed research models are open.

🇨🇳 ChinaClosed

Spark (X1)

iFlytek · Public, partially state-owned (SZSE: 002230)
34/100High risk
Proprietary (specialized variants Apache 2.0) · Hosted only

Partially state-owned Chinese vendor; the flagship Spark X1 is a closed, hosted model trained on domestic compute. Hosted data falls under PRC law, and the model is on US export/entity-list scrutiny — high risk for Western data.

🇨🇳 ChinaMixed

SenseNova (U1)

SenseTime (商汤) · Public (HKEX: 0020); US-sanctioned entity
34/100High risk
Open-weight (U1 variants) / proprietary (flagship) · Self-hostable

Chinese vendor on the US sanctions/entity list. Flagship SenseNova is closed and hosted under PRC law, though some U1 multimodal variants are open-weight and self-hostable. High risk for a US business given sanctions exposure.

🇨🇳 ChinaClosed

Kling (3.0 / O1)

Kuaishou · Public (HKEX: 1024)
34/100High risk
Proprietary · Hosted only

Beijing-based Kuaishou; Kling is a closed, hosted-only video model. Uploaded content is processed in the PRC under PRC law and can be used to improve the service, with no self-hosting option — high risk for sensitive material.

Where the Major AI Companies Are Based

Most leading AI models come from the United States or China, with a smaller cluster in Europe. Here is where the companies behind the best-known models are headquartered.

  • American AI models: ChatGPT and GPT-5 (OpenAI), Claude (Anthropic), Gemini and Gemma (Google), Llama (Meta), Phi (Microsoft), Grok (xAI), and Nova (Amazon) are all based in the United States.
  • Chinese AI models: DeepSeek, Qwen (Alibaba), ERNIE (Baidu), GLM (Z.ai), Kimi (Moonshot), Hunyuan (Tencent), Doubao (ByteDance), MiniMax, and Yi (01.AI) are based in China.
  • European AI models: Mistral is based in France; Aleph Alpha (Pharia) and Black Forest Labs (FLUX) are in Germany; and Stability AI is in the United Kingdom.
  • Other regions: Cohere is Canadian, AI21 (Jamba) is Israeli, Falcon (TII) is from the UAE, SEA-LION is from Singapore, Sarvam and Krutrim are Indian, HyperCLOVA X, EXAONE, and Solar are South Korean, and Sakana AI and NTT (tsuzumi) are Japanese.

Why Country of Origin Matters for Business

The country that controls an AI vendor controls the legal reach over your company data. A China-hosted API processes your prompts under PRC laws such as the National Intelligence Law. US vendors fall under the CLOUD Act, and EU vendors under GDPR. For regulated or sensitive business data, that jurisdiction is often the deciding factor.

Open weights change the math. When a model is open and your team self-hosts it, your data never leaves your infrastructure, so the vendor's home country stops mattering for privacy. This is why a self-hosted Chinese open-weight model can be safer than a closed US API for sensitive workloads. The deployment, not just the flag, drives the real risk.

In practice, the blocker we see stall AI projects is rarely the model's quality. It is a procurement or compliance team asking where the data goes and which law applies. This page is built to answer that question first.

How the Business Safety Score Works

Each model gets a score from 0 to 100, where higher means lower risk for a business handling real customer or company data. The score is computed the same way for every model from five equally weighted dimensions, so it is reproducible rather than an opinion.

Dimension (0–20 each)What it measures for your business
Jurisdiction & data accessHome-country rule of law and government data-access regime for the hosted API.
Data privacy / training defaultWhether the provider trains on your inputs, and if zero-retention is available.
Compliance certificationsSOC 2, ISO 27001, HIPAA BAA, and GDPR DPA availability.
Deployment controlOpen weights (self-host) vs private/VPC vs API-only.
Transparency & accountabilityClear terms, vendor maturity, and security track record.
  • 80–100 — Low risk: safe default for most business data.
  • 65–79 — Moderate risk: fine with standard controls and review.
  • 50–64 — Elevated risk: use with care; prefer self-hosting where open.
  • Below 50 — High risk: avoid for sensitive business data without legal review.

Scores reflect the typical hosted-API deployment most businesses use. For open-weight models, the note on each card explains how self-hosting lowers the real risk. Where a fact could not be confirmed from a primary source, the dimension is scored conservatively as unknown rather than guessed.

Researched and reviewed by Jonathan West, Founder of Layer3Labs, using each vendor's own privacy policies, trust centers, and license terms. Last updated July 2026; the AI landscape moves fast, so verify current terms before a final decision. Learn more about our team and approach.

Frequently Asked Questions

Where is OpenAI based?

OpenAI, the company behind ChatGPT and GPT-5, is based in San Francisco, California, in the United States. As a US company, its API and enterprise data are subject to US law.

Is ChatGPT American?

Yes. ChatGPT is made by OpenAI, an American company headquartered in San Francisco. Business data sent to the ChatGPT or GPT API is processed under US jurisdiction.

Is DeepSeek Chinese?

Yes. DeepSeek is a Chinese AI company based in Hangzhou, China. Its hosted API stores data in China under PRC law, but its open weights are MIT-licensed and can be self-hosted outside China.

Where is Mistral AI based?

Mistral AI is based in Paris, France. As an EU company it operates under GDPR, with EU data residency and zero-retention options available for business customers.

Where is Anthropic (Claude) based?

Anthropic, the maker of Claude, is based in San Francisco, California, in the United States. Claude’s API and enterprise data are not used for training and fall under US jurisdiction.

Which AI models are Chinese?

The major Chinese AI models are DeepSeek, Qwen (Alibaba), ERNIE (Baidu), GLM (Z.ai/Zhipu), Kimi (Moonshot), Hunyuan (Tencent), Doubao (ByteDance), MiniMax, and Yi (01.AI). Most are open-weight, which matters for business: the data-jurisdiction risk applies to their China-hosted APIs, not to the weights you download and self-host.

Are Chinese AI models safe for business?

It depends entirely on how your business deploys them. Using a China-hosted API means your company prompts are processed in the PRC under laws like the National Intelligence Law, which is an elevated risk for business data. Because most Chinese models are open-weight, self-hosting them outside China removes that jurisdiction exposure.

Which AI models are safest for business use?

For business, the highest-scoring models are US and European ones with enterprise terms: no training on your inputs, SOC 2 / ISO certifications, and VPC or self-hosting options. Microsoft Phi, Amazon Nova, Anthropic Claude, Google Gemini, and Meta Llama all score in the low-risk tier on our rubric.

How is the business safety score calculated?

Each model is scored from 0 to 100 across five equally weighted dimensions: legal jurisdiction and government data-access risk, data-privacy and training-default policy, compliance certifications, deployment control, and vendor transparency. Scores are computed the same way for every model, not assigned by hand.

Does an open-weight model remove data-privacy risk for a company?

Largely, yes. When your company self-hosts open weights on its own infrastructure, no prompts leave your environment and the vendor has no visibility into your data, regardless of where the company is based. Your team then owns its own security and compliance controls.

The Bottom Line

For business use, an AI model's country and deployment matter as much as its quality. US and European models with no-train terms and strong certifications score safest, China-hosted APIs carry the most jurisdiction risk, and open weights let you self-host to neutralize that risk entirely. Use the score as a starting filter, then confirm current terms with the vendor before you commit.

Keep exploring with our self-hosted AI models guide, head-to-head AI comparisons, and AI implementation guides.

Not Sure Which Model Fits Your Business?

The right model depends on your data sensitivity, budget, and compliance needs. Book a free AI workflow audit and we will recommend the safest model that fits your use case — and wire it into your tools.

Book your free audit