Data residency

Sovereign AI in Australia: what it means and how to choose tools

Sovereign AI means different things to different people. This guide separates the five layers people usually mean, explains the US CLOUD Act and the Australia-US data access agreement honestly, and gives you a framework for choosing AI tools.

By the AusGPT team · Updated · 6 min read

General information only, not legal advice. Check the primary sources linked below, and get advice for your situation.

Sovereign AI in Australia usually means AI that keeps Australian data under Australian control. But "control" has several layers, and most people asking "what is sovereign AI?" care about one or two of them, not all five. A tool can store everything in Sydney and still be operated by a US company; a model can be trained in Melbourne and still run on imported chips.

This guide separates those layers, explains what the US CLOUD Act and the Australia-US data access agreement actually do, summarises Australian initiatives you can verify, and gives you a practical framework for choosing tools.

What is sovereign AI? The five layers

Layer The question it answers What "sovereign" looks like
Data location Where are prompts, documents and outputs stored? Stored only in Australian data centres, including backups and logs
Processing location Where does the model actually run (inference)? Requests processed only in Australia, never routed offshore
Operator jurisdiction Which company runs the service, and which countries' laws apply to it? An operator subject only to Australian law
Model ownership Who built and controls the model weights? A model trained and controlled in Australia
Compute Who owns the chips and data centres? Australian-controlled infrastructure

Some people add a sixth: skills and talent, meaning whether Australia has the people to build and run these systems.

These layers are independent. Data residency (the first two) is the most common requirement and the easiest to verify. The last three are where "sovereign" claims usually get vague, so ask vendors about each layer separately.

Why it matters for Australian organisations

Privacy law. Under Australian Privacy Principle 8, before disclosing personal information to an overseas recipient you must take reasonable steps to make sure it won't breach the APPs, and under section 16C you can be held accountable for what that recipient does. The OAIC says that sending information to an overseas cloud provider only for storage, while you keep effective control, may be a "use" rather than a "disclosure", but the information is still yours to protect. Keeping storage and processing in Australia simplifies that analysis.

Sector and contract rules. Health, legal, government and financial services clients often ask where data goes before they ask anything else.

Foreign law. If your provider is headquartered in another country, that country's laws may reach data the provider controls. For most Australian organisations the relevant one is the United States.

The US CLOUD Act, explained honestly

The CLOUD Act was passed in the United States in 2018. One of its provisions, 18 U.S.C. § 2713, says US communications and cloud providers must comply with US legal obligations to preserve or disclose data in their "possession, custody, or control, regardless of whether" it is located inside or outside the United States.

What that means in practice:

  • Residency alone doesn't remove US legal reach. Data held in Sydney by a US-headquartered provider is in Australian data centres, but the provider can still be served with lawful US process.
  • It works through legal process, not open access. The obligation is to comply with lawful US process served on the provider. Providers can also challenge some requests: § 2703(h) lets a provider move to modify or quash process where it reasonably believes the customer is not a US person and doesn't live in the US, and disclosure would create a material risk of breaking the laws of a "qualifying foreign government".

The Australia-US data access agreement. Australia and the US signed the Agreement on Access to Electronic Data for the Purpose of Countering Serious Crime (often called the CLOUD Act Agreement) on 15 December 2021, and it entered into force on 30 January 2024. According to the Attorney-General's Department:

  • it lets each country's law enforcement and national security agencies seek data directly from communications providers in the other country, through a designated authority (for Australia, the Attorney-General's Department)
  • orders must relate to offences punishable by at least three years' imprisonment and are subject to independent review or oversight
  • US authorities cannot intentionally target Australian citizens, permanent residents or anyone residing in Australia under the agreement (and Australian agencies can't intentionally target US citizens or anyone in the US); requests about those people still go through existing channels such as mutual assistance

The honest summary: Australian residency with a US provider reduces many risks (offshore processing, foreign data centres, unclear subprocessors), and the agreement adds safeguards for Australians. It does not make data legally unreachable by the provider's home country. If your risk assessment requires that, you need an operator outside US jurisdiction, which narrows your options considerably.

What Australia is doing

These are initiatives you can check against official or company sources, described as at October 2026.

  • National AI Plan. The Australian Government's National AI Plan rests on three pillars: harnessing the benefits of AI, sharing the benefits, and keeping Australians safe. In July 2026 ministers said the Australian AI Safety Institute had begun safety testing of frontier AI systems.
  • GovAI. The Department of Finance runs GovAI, a whole-of-government service that provides "secure, Australian-based infrastructure" for public servants and access to onshore instances of OpenAI's GPT models and Anthropic's Claude. Even the Commonwealth's own platform pairs onshore hosting with models built overseas.
  • Local models. Melbourne company Maincode opened its Matilda chat model and coding agent to a broader beta in July 2026, saying it is built and served from its own hardware in Melbourne. Sovereign Australia AI announced in September 2025 that it had ordered 256 Nvidia B200 GPUs, hosted by NEXTDC, to build models called Ginan and Australis. Test any local model against your own tasks before relying on it.

A practical framework for choosing AI tools

Step 1: Classify the data. What will staff actually put into the tool? Public material, internal business information, personal information, sensitive or health information, legally privileged or classified material.

Step 2: Decide which layers you need.

Data type Minimum sensible layers
Public or marketing content Any reputable tool with no training on your inputs
Internal business information Contractual confidentiality, no training on inputs, known storage location
Personal information Australian storage and processing, no training, clear retention and access controls
Sensitive, health or privileged information All of the above, plus de-identification where possible and a documented privacy assessment
Classified or national security information Government-assessed services only; follow your agency's requirements

Step 3: Ask vendors specific questions.

  • Where are prompts, files, outputs, logs and backups stored?
  • Where does inference run? Can requests ever be routed offshore?
  • Which subprocessors handle the data, and where?
  • Are inputs or outputs used to train any model, by the vendor or the model provider?
  • How long is data retained, and can we delete it?
  • Which company operates the service, and where is it headquartered?
  • What do the contract terms say about confidentiality and government access requests?

Step 4: Record the decision. Document which layers you required, which the tool meets, and the residual risks you accepted. That record is what a board, auditor or client will ask for.

Where AusGPT fits

AusGPT is designed for the data residency and processing layers, and we're explicit about the rest:

  • Processing in Australia. AI responses come from Anthropic's Claude models through Amazon Bedrock's Australian cross-region inference profile, which AWS says routes requests only between its Sydney and Melbourne regions.
  • Storage in Australia. AusGPT is hosted on AWS in Sydney, where conversations and documents are stored.
  • No training on your data. Customer data isn't used to train AI models, and Bedrock doesn't share prompts or responses with Anthropic or other model providers.
  • Not fully sovereign. AWS is a US-headquartered company and Anthropic is a US company, so AusGPT does not claim sovereignty on the operator jurisdiction or model ownership layers.

For comparison, as of October 2026 Anthropic's own API offers only global or US inference, with US storage for API workspaces, so the Bedrock Australian profile is how we keep Claude processing onshore. If your assessment calls for Australian residency and processing with a leading model, AusGPT fits. If it calls for an operator outside US jurisdiction, look at local providers and weigh the trade-offs. Read more about how we keep Claude in Australia or on our security page.

Use Claude with processing in Australia

AusGPT gives your team Claude AI with conversations and documents stored and processed in Australia. $29 per user per month, with a free trial.

Frequently asked questions

What is sovereign AI?
Sovereign AI describes AI that a country, or an organisation within it, controls under its own laws. In practice people mean one or more of five layers: where data is stored, where it is processed, which country's law governs the operator, who owns the model, and who owns the compute it runs on. Very few services are sovereign on every layer, so it's more useful to ask which layers you need.
Is data stored in Australia safe from the US CLOUD Act?
Not automatically. US law requires US providers to comply with lawful disclosure obligations for data in their possession, custody or control regardless of whether it is stored inside or outside the United States. Storing data in Australia with a US-headquartered provider keeps it in Australian data centres but doesn't by itself take it outside US legal process. The Australia-US data access agreement adds safeguards, including that US authorities cannot intentionally target Australian citizens, permanent residents or people in Australia under the agreement.
What is the difference between data residency and data sovereignty?
Data residency is about where data physically sits. Data sovereignty is about which laws and authorities can reach it. Residency in Australia is necessary for sovereignty but not sufficient on its own, because the operator's home jurisdiction can also matter.
Does Australia have its own sovereign AI model?
There are local efforts. Melbourne company Maincode opened its Matilda model to a broader open beta in July 2026, served from its own hardware in Melbourne, and Sovereign Australia AI announced plans in 2025 to build models called Ginan and Australis on GPUs hosted by NEXTDC. The Australian Government's GovAI platform offers public servants onshore instances of models from OpenAI and Anthropic rather than a government-built model.
Is AusGPT sovereign AI?
AusGPT provides Australian data residency and processing: Claude requests are processed in AWS Sydney and Melbourne, and conversations and documents are stored in AWS Sydney. It runs on Amazon Web Services, a US-headquartered company, and uses Anthropic's Claude models, so it does not claim full sovereignty on the operator or model ownership layers.

Secure AI for your team, processed in Australia

Claude AI, document chat and voice dictation, with your data stored and processed in Australia. $29 per user per month.