Which AI Vendors Keep Data in Canada? A 2026 Comparison

data residencyCanadaPIPEDALaw 25AI vendors

Most "AI vendors keep data in Canada" claims turn out to describe where servers physically sit, not who legally controls the data running through them — and that gap is what a PIPEDA accountability review, a Law 25 cross-border assessment, or an OSFI Guideline E-23 model-risk file actually tests. Checking each major vendor's own documentation directly, the picture is uneven: Google's Gemini is the only proprietary frontier model with confirmed true in-region processing in Canada (Montreal). Cohere, a Toronto-headquartered company, is the only vendor that can plausibly clear a Law 25-style assessment on its own corporate jurisdiction, via private deployment. Claude has no genuine single-region guarantee in Canada on any of its three enterprise channels. OpenAI's frontier GPT-5.6 tier is not regionally pinned on Azure in Canada at all. xAI and Mistral offer no confirmed Canadian processing option. The only architecture that removes the question entirely is a self-hosted open-weight model on hardware a Canadian organization owns.

Which AI vendors offer real Canadian data processing?

Vendor Canadian processing region? Zero-retention / no-training terms On-prem option What still leaves Canada Verdict under PIPEDA / Law 25 / OSFI E-23 / PHIPA
Anthropic (Claude) No true in-region guarantee. Bedrock's Canada (Central) region offers only "Geo" or "Global" cross-region inference for Claude — no in-region routing exists (AWS docs); AWS states prompts "might move outside of your source Region" even under Geo routing (AWS blog). Vertex AI has no Canada multi-region or regional endpoint for Claude, only global or US/EU multi-region (Claude on Vertex AI docs). Microsoft Foundry still runs Claude on Anthropic-hosted infrastructure, not Azure infrastructure in-region (source). No training by default for Claude for Work/Enterprise; ZDR available on application. New "Enterprise Frontier Safeguards" (Sept 2026) store data on customer-controlled infrastructure but Anthropic keeps a standing read permission for trust-and-safety — described as "zero data custody," not true zero retention (The Register). None found. Everything, by default — no channel guarantees Canadian in-region processing; US company, CLOUD Act applies regardless of route chosen. Fails a strict cross-border assessment; treat as fully outside Canada unless self-hosted.
OpenAI (GPT-5.6) Azure OpenAI Data Zones cover only US and EU — no Canada zone (Azure blog). Azure's Canada Central/Canada East regions support single-region "Standard" deployment, but only for retiring legacy models; the GPT-5 family is available only as Global Standard, Global Provisioned Managed, or Regional Provisioned Managed — none of which pin to Canada alone (Microsoft Learn). OpenAI's direct API offers contractual data-residency in a defined country list that includes Canada, at a 10% price uplift for models released after March 5, 2026 (OpenAI; Wavect). No training on API/Enterprise data by default since March 2023; 30-day abuse-monitoring retention otherwise; ZDR available for eligible enterprise endpoints (OpenAI enterprise privacy). Emerging — OpenAI/Dell partnership (announced May 18, 2026) brings Codex, not the full GPT-5.6 line, to hybrid/on-prem infrastructure; pricing undisclosed (Dell newsroom). The frontier model itself, on Azure, in Canada — the flagship tier simply isn't regionally pinned there; direct-API residency is a contractual promise, not a jurisdiction change. Fails for the frontier tier on Azure in Canada; direct-API residency helps the paper trail but not the CLOUD Act analysis — US company regardless.
Google (Gemini) Confirmed true in-region ML processing in Montreal (northamerica-northeast1) for Gemini 2.5 Pro/Flash, Gemini 2.0 Flash, and related embeddings — not just storage (Google Canada blog). Google's Vertex AI generative AI terms are documented as not using enterprise customer prompts/outputs to train Google's models by default (Vertex AI data governance docs — general policy; specific clause not independently re-verified in this review). Yes — Gemini on Google Distributed Cloud, Dell-built on NVIDIA Blackwell, deployable air-gapped inside a customer facility; GA targeted Q3 2026 (VentureBeat). Google remains a US company subject to the CLOUD Act even when processing stays physically in Montreal; support and account-management functions are not necessarily Canada-based. Best "Canada region" story among proprietary vendors for the residency question specifically; CLOUD Act exposure is unchanged regardless.
xAI (Grok) No confirmed Canadian region. Vendor states general API "data residency" without a per-country breakdown independently verified against a signed DPA or SOC 2 report (x.ai/api; TechJack). Grok Business: no training on data by default, SOC 2 Type II. Grok Enterprise adds SSO, SCIM, audit logs, "secure data vaults" — vendor-stated. None found. Everything — no confirmed Canadian processing option at all. Fails outright; no basis for a Canadian residency claim in vendor documentation reviewed.
Cohere Toronto-headquartered company. Public SaaS API and marketplace listings (AWS Bedrock, Azure) don't themselves guarantee Canadian processing, but private deployment runs models inside a customer's own VPC, private cloud, or fully on-premises/air-gapped, with data never leaving the customer's perimeter (Cohere private deployment docs; Cohere). Bell Canada and SAP partnerships extend Canadian-hosted sovereign infrastructure (BetaKit; SAP Canada). Enterprise customers "control how we train on their data" via DPA; default Platform retention is ~30 days for enterprise use (Cohere privacy). Yes — VPC, private cloud, on-premises, and air-gapped configurations are explicitly supported. Only the public SaaS API path, if used without a Canadian-hosted or private deployment. The only proprietary vendor here whose corporate jurisdiction itself is Canadian — private/Bell-hosted deployment is the strongest non-self-hosted answer to a Law 25 assessment.
Mistral AI No Canada regional endpoint. Regional Endpoints cover Europe or US only, billed at 1.1× list price (Mistral). Not independently confirmed in this review — unconfirmed. Only via self-hosting Mistral's smaller Apache-licensed open-weight models yourself; the flagship models are not open weight. Everything, on the hosted API — data processes in the EU or US regardless of the customer's location. Fails on residency; a France-headquartered vendor avoids CLOUD Act exposure specifically, but that doesn't satisfy a "stays in Canada" requirement, since nothing routes there.
Self-hosted open weights (GLM-5.3, DeepSeek, Qwen, Llama, Kimi K3) The only option with a static, verifiable answer: wherever you put the hardware. N/A — no vendor is in the data path to retain or train on anything. This is the on-prem option. Nothing, by construction — no provider holds the data at any point. Clears PIPEDA, Law 25's cross-border assessment, OSFI E-23's third-party risk concerns, and PHIPA's disclosure-control duties by removing the question, not by winning the assessment.

What do "Canada region" claims actually mean, once you check the vendor's own docs?

The pattern across every proprietary vendor reviewed is the same: "available in Canada" and "processed only in Canada" are different claims, and marketing pages routinely blur them. AWS Bedrock has been generally available in the Canada (Central) region since June 2024, and Claude models are reachable from there — but reachable is not the same as pinned. Bedrock's own regional-compatibility documentation shows Claude supporting only "Geo" cross-region inference (which keeps processing inside a defined geography, not a single region) or "Global" routing in ca-central-1, with no in-region option listed at all. AWS's own blog post announcing Canadian cross-region inference states plainly that "your input prompts and output results might move outside of your source Region during cross-Region inference" — a materially weaker guarantee than the true in-region processing Anthropic and Google both offer EU customers in Frankfurt, Dublin, or Paris.

Google is the outlier in the other direction. Its own Canadian announcement states plainly that ML processing — not just storage — for Gemini happens inside the Montreal region when a customer selects it, a stronger and more specific claim than any other vendor in this review makes for Canada specifically. That single fact is the reason Gemini leads this comparison on the residency question alone, even though it changes nothing about Google's status as a US company under the CLOUD Act.

OpenAI's gap is structural rather than a documentation shortfall: Azure's Data Zone product, which is Microsoft's real regional-pinning mechanism, simply hasn't been built for Canada — it covers US and EU only. Canada Central and Canada East exist as Azure regions and do support single-region "Standard" deployment, but only for the legacy models being retired through October 2026; the current GPT-5 family isn't offered there at all under a regional guarantee. The only Canada-capable path for OpenAI's current frontier tier is the direct API's data-residency program, which is a contractual location promise layered on top of a US company — useful for a PIA, but it doesn't touch the CLOUD Act analysis our companion piece on 18 USC 2713 walks through.

What still leaves Canada even after you pick the "Canada" setting?

Three things, consistently, across every proprietary vendor in this table: the provider's jurisdiction, which determines whether the CLOUD Act or an equivalent foreign-disclosure statute can reach the data regardless of server location; support and account operations, which routinely run through teams outside the processing region even when inference itself is pinned; and telemetry, abuse-monitoring, and safety-classifier data, which several vendors — Anthropic and OpenAI both say so explicitly — retain outside the customer's chosen retention terms as a carve-out for misuse detection. A Canadian AWS region, a Canadian Azure region, or a Canadian-labeled data-residency tier addresses none of these. Our Quebec Law 25 guide and OSFI Guideline E-23 guide cover why that distinction is the one regulators and examiners actually test.

How do you decide which tier handles which data?

The pattern that works in practice, and the one our frontier-and-routing practice builds for clients, is a classification exercise before a vendor selection:

  1. Public or already-published material — marketing copy, public filings, published research — can go to any frontier API, Canadian region or not, since nothing sensitive is at risk if a support engineer or a compelled disclosure sees it.
  2. De-identified or aggregate data — anonymized analytics, synthetic test data — can reasonably use a frontier model through a region-pinned endpoint where one genuinely exists (Gemini on Vertex in Montreal is the clean case; Claude and GPT-5.6 currently are not).
  3. Anything that identifies a client, patient, employee, or claimant — the material Law 25, PIPEDA, PHIPA, and OSFI E-23 actually govern — should not go to a proprietary vendor at all, Canadian-labeled or not, because every vendor in this comparison remains a third party capable of retaining, logging, or being compelled to produce it. This tier belongs on self-hosted open weights.

Financial institutions layering OSFI E-23's model-risk lifecycle on top of this classification get an additional reason to prefer the third tier: a self-hosted model is a pinned, checksummed artifact you can validate once and re-validate on your own schedule, where a vendor's Canada-labeled endpoint can still change model versions, routing behavior, or retention terms without your sign-off.

Why is self-hosted open weights the only option with nothing leaving Canada?

Because it is the only architecture in this comparison where there is no vendor to check. Every proprietary row in the table above — even Gemini's genuine in-region processing, even Cohere's Canadian headquarters and private-deployment option — still involves a company that receives the data, however briefly, and that company's own terms, jurisdiction, or support operations govern what happens next. A self-hosted deployment of GLM-5.3, DeepSeek, Qwen, or Kimi K3 removes that party entirely: the model is a downloaded, checksummed file running on hardware a Canadian organization owns, on premises or in a Canadian colocation rack, with zero data egress by construction. There is no Canada-region setting to select, no cross-region inference profile to read the fine print on, and no vendor DPA to renegotiate when the next model version ships — because there is no vendor in the loop at all.

Questions we get

Frequently asked questions

Which AI vendors let you keep data in Canada?

Google's Gemini has the strongest confirmed story: Vertex AI's Montreal region (northamerica-northeast1) performs genuine in-region ML processing, not just storage. Cohere, a Toronto-headquartered company, offers private deployment into a customer's own VPC or on-premises environment, including partnerships with Bell Canada for Canadian-hosted infrastructure. Claude, GPT-5.6, Grok, and Mistral do not currently offer a confirmed true in-region processing guarantee inside Canada — their 'Canada region' options are either cross-region routing, legacy-model-only, or unavailable.

Does using a Canadian AWS or Azure region make an AI tool PIPEDA or Law 25 compliant?

Not by itself. Region selection controls where bytes are processed or stored; it does not change which company is legally in possession of the data or what law can compel that company to disclose it. A US-headquartered AI vendor remains subject to the US CLOUD Act regardless of the AWS, Azure, or Google Cloud region selected, which is the exact scenario Law 25's cross-border 'equivalent protection' assessment and PIPEDA's accountability principle are built to catch.

Is Claude available in a Canadian data region?

Not with a true single-region guarantee, as of September 2026. On Amazon Bedrock, Claude in the Canada (Central) region only supports 'Geo' or 'Global' cross-region inference — AWS's own documentation states prompts and outputs may move outside the source region during that routing. On Google Vertex AI, Claude has no Canada-specific multi-region or regional endpoint at all, only global or US/EU multi-region options. On Microsoft Foundry, Claude still runs on Anthropic-hosted infrastructure rather than Azure infrastructure in the selected region.

What is the only AI architecture where nothing leaves Canada?

A self-hosted open-weight model — such as GLM-5.3, DeepSeek, Qwen, or Kimi K3 — running on hardware a Canadian organization owns, on premises or in a Canadian colocation rack, with no vendor holding the data. Every proprietary vendor, including the ones with a Canadian office or a Canadian-region option, remains a third party in possession of the data at some point in the pipeline; a self-hosted model removes that party entirely.

Take the 40 Claude skills and the briefing with you

The Vault 2026 skills pack (calendar audits, hiring scorecards, calibration, continuity plans) plus the sovereignty briefing: model releases, deployment economics and regulatory shifts for regulated firms. One click to unsubscribe.

Free. You get the Vault 2026 skills pack now and the sovereignty briefing roughly monthly. One-click unsubscribe.

Ready to move from reading to running?

We design, build, fine-tune, host, and maintain sovereign AI deployments end to end.

Book a sovereignty assessment How deployment works