LLM Provider Compliance Postures Compared (HIPAA / SOC 2 / EU)
The compliance postures of major LLM providers in 2026 — HIPAA BAA, SOC 2, EU AI Act, ISO 42001 — compared side by side.
Why Compliance Decides Provider Choice
For regulated workloads, the compliance posture of an LLM provider matters as much as quality. A provider without a HIPAA BAA cannot legally process PHI. A provider without SOC 2 won't pass an enterprise procurement review. A provider without EU residency may not be deployable to European customers.
This piece compares 2026 compliance postures across major providers.
The Compliance Matrix
flowchart TB
Workload[Regulated workload] --> Q1{HIPAA?}
Workload --> Q2{SOC 2 required?}
Workload --> Q3{EU residency?}
Workload --> Q4{EU AI Act?}
Q1 -->|Yes| BAA[BAA-tier provider only]
Q2 -->|Yes| Soc[Verify SOC 2 Type II report]
Q3 -->|Yes| Region[Region-pinned endpoints]
Q4 -->|Yes| Code[Code of Practice signatory]
| Provider | HIPAA BAA | SOC 2 | ISO 27001 | EU residency | EU AI Act readiness |
|---|---|---|---|---|---|
| OpenAI | Yes (Enterprise) | Yes | Yes | Yes (Azure OpenAI) | In progress |
| Anthropic | Yes | Yes | Yes | Yes | In progress |
| Google Vertex | Yes | Yes | Yes | Yes | Strong |
| AWS Bedrock | Yes | Yes | Yes | Yes | Strong |
| Microsoft Azure | Yes | Yes | Yes | Yes | Strong |
| Open-weights self-hosted | You | You | You | You | You |
The major closed providers all have BAAs and SOC 2 in 2026; open-weights you carry the burden.
HIPAA BAA Specifics
A BAA is a Business Associate Agreement under HIPAA, where the provider agrees to handle PHI compliantly. By 2026, the Enterprise tier of most major providers includes one. Free / starter tiers typically do not.
For HIPAA workloads:
- Sign the BAA before sending any PHI
- Use the BAA-covered API endpoints (often a separate URL)
- Verify the audit logging meets HIPAA requirements
SOC 2 vs ISO 27001
SOC 2 is the US-flavored audit; ISO 27001 is international. Both demonstrate operational security maturity.
Hear it before you finish reading
Talk to a live CallSphere AI voice agent in your browser — 60 seconds, no signup.
For B2B procurement in 2026, SOC 2 Type II is essentially required; ISO 27001 is preferred for international customers.
EU AI Act
The EU AI Act's GPAI provider obligations apply to LLM providers. By 2026:
- Providers that signed the Code of Practice are largely compliant
- Compliance materials (technical files, training-data summaries) are public
- New regulatory clarifications continue through 2026
For deployers in the EU, picking a provider that is itself compliant is the simplest path; the deployer's own obligations are reduced.
Data Residency
For workloads that cannot leave specific jurisdictions:
- US: most providers offer
- EU: most major providers; verify the specific endpoint
- Other regions: Google strongest; AWS via Bedrock; OpenAI via Azure
For some specific jurisdictions (China, Russia), most US providers are not deployable.
Training-Data Use
The 2026 default for enterprise tiers: customer data is NOT used for training. Verify this in the contract. Free / starter tiers often have different defaults.
Audit Logging
For compliance, you need audit logs of:
Still reading? Stop comparing — try CallSphere live.
CallSphere ships complete AI voice agents per industry — 14 tools for healthcare, 10 agents for real estate, 4 specialists for salons. See how it actually handles a call before you book a demo.
- Every API call
- Inputs and outputs (or at least metadata)
- User identity (if pass-through auth)
- Timestamps
Provider-side audit logs vary in detail. Most enterprises supplement with their own gateway-level logging for completeness.
Specific Compliance Questions
When evaluating a provider, ask:
- BAA available? At which tier?
- SOC 2 Type II report current? Can we see it?
- Is our data used for training? Default and configurable?
- Where is data stored? Per region.
- Subprocessors used? List?
- Data retention default? Configurable?
- Incident notification SLA?
A vendor that cannot answer these has not done the compliance work.
Multi-Provider Considerations
For multi-provider failover with regulated workloads:
- All providers must have the relevant compliance posture
- BAAs with each
- Same data-residency
- Same training-data terms
Some teams reduce to a single regulated provider for compliance simplicity.
Open-Weights Compliance
Self-hosted open-weights:
- You inherit all compliance burden
- HIPAA: your infrastructure must be BAA-friendly (AWS, Azure, GCP all support)
- SOC 2: your operational practices, audited by your own auditors
- EU AI Act: as deployer rather than provider
For regulated customers, self-hosting requires substantially more compliance investment but gives full control.
Sources
- OpenAI compliance — https://openai.com/security
- Anthropic security — https://trust.anthropic.com
- Google Cloud compliance — https://cloud.google.com/security/compliance
- AWS Bedrock security — https://aws.amazon.com/bedrock/security
- HIPAA Privacy Rule — https://www.hhs.gov/hipaa
Try CallSphere AI Voice Agents
See how AI voice agents work for your industry. Live demo available -- no signup required.