Australian Hosted AI: How to Audit a Vendor Claim - Zian AI

Australian Hosted AI: How to Audit a Vendor Claim

Australian Hosted AI: How to Audit a Vendor Claim

“Hosted in Australia” usually describes storage at rest, not model inference. Under APP 8.1 of the Privacy Act 1988 (Cth) and s 16C, the disclosing entity stays accountable for an overseas recipient’s handling. Audit six layers separately — storage, processing, inference, support access, backups, logs — and demand a named region code and a dated artefact for each.

At a glance:

  • Storage is not inference. A vendor can truthfully store recordings in Sydney while the audio round-trips to an offshore inference endpoint mid-call.
  • Region codes are the unit of audit. “Australia” is marketing; ap-southeast-2, australia-southeast1 and australiaeast are auditable.
  • Multi-region and global endpoints are the usual gap. Google states that endpoints “don’t guarantee data residency or in-region ML processing”.
  • APP 8.2 sets out exceptions. A vendor may be relying on one. Ask which limb, in writing.
  • IRAP is not a certification. ASD says assessors “do not accredit, certify, endorse or register systems on behalf of ASD”.
  • Ask for logs, not badges. An inference-location log field beats a trust page.

What “hosted in Australia” does and does not cover

The sentence does less work than it appears to. A voice agent is a chain of services, and “hosted” typically refers to one link: where the vendor’s own application servers and primary database run. Our guide to AI voice agent data residency walks that chain hop by hop; this post is the audit of it.

Split the claim into six questions, each with its own artefact. Storage at rest: where recordings, transcripts and embeddings sit — a region code plus a resource ID showing the region. Application processing: where orchestration runs — a deployment manifest or console screenshot. Model inference: where audio is transcribed and speech synthesised — the production endpoint or model ID, and the routing policy behind it. Support access: which humans, in which countries, can open a transcript — a list of support jurisdictions and an access-log export. Backups: destination region and retention period. Logs and telemetry: error trackers are a real egress path — a subprocessor list with each one’s processing region.

Where the claim usually breaks: speech and model inference

The Australian cloud regions are real. AWS lists Amazon Bedrock control-plane endpoints in both ap-southeast-2 (Sydney) and ap-southeast-4 (Melbourne) on its Bedrock endpoints and quotas page. Google lists Sydney (australia-southeast1). Azure lists Australia East. The region existing is not the question; what happens to a single request is. Three provider statements, from their own documentation, checked 4 September 2026:

AWS. On Supported Regions and models for inference profiles: “When using a cross-Region inference profile, your inference request can be routed to any of the destination Regions in the profile, even if you did not opt-in to such Regions in your account. Your input prompts and output results may be stored in the opt-in Regions for abuse detection purposes.” The same page states that “The destination Regions for Global cross-Region inference profiles include all commercial Regions”, and also that the Global profile “is currently only supported on Anthropic Claude Sonnet 4 model” for five listed source Regions, none of them Australian. The cross-Region inference page distinguishes Geographic profiles (“Routed within the geography”, geographies “such as US, EU, and APAC”) from Global (“Routed worldwide”). This is documented, configurable behaviour rather than a defect: the same page tells buyers to “Choose Geographic cross-Region inference when you have data residency requirements”, and AWS notes that Service Control Policies and IAM policies “work together to control where cross-Region inference is allowed”. But APAC is a geography, not Australia — a Sydney-sourced request on an APAC profile can be inside the vendor’s stated boundary and outside Australia at the same time.

Google. Its generative AI deployments and endpoints page carries an explicit warning: “Endpoints don’t guarantee data residency or in-region ML processing.” The matching data residency page separates the two concepts — data at rest “remains at rest in that location, independent of the … endpoint called by that customer’s request”, while for ML processing “The geographic location of this processing is determined by your choice of endpoint”.

Microsoft. On Foundry Models sold by Azure, Microsoft states that “Global training provides more affordable training per token, but doesn’t offer data residency”, and lists Australia East among the regions where it is available. That sentence is about training, not inference — exactly the distinction a buyer must read for rather than skim.

Speech is where availability actually thins out. On the Amazon Transcribe endpoints page, ap-southeast-2 (Sydney) appears in both the batch and the streaming endpoint tables. ap-southeast-4 (Melbourne) appears in neither, checked 4 September 2026. A vendor whose infrastructure sits in Melbourne and whose ASR is Amazon Transcribe is therefore streaming audio somewhere else. That is not a scandal. It is a fact a buyer is entitled to have named.

What we could not determine. Google’s Speech-to-Text V2 regional availability page publishes no static region table — “To understand the availabilities, use the Locations API” — so we could not confirm from that page which speech models run in australia-southeast1, checked 4 September 2026. If your vendor relies on it, that is a question for them, with a screenshot as the answer.

The legal hook: APP 8.1, s 16C and the exceptions

APP 8.1 of the Privacy Act 1988 (Cth) requires that before an APP entity discloses personal information to an overseas recipient, “the entity must take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles (other than Australian Privacy Principle 1) in relation to the information” (Schedule 1, legislation.gov.au).

Section 16C supplies the teeth. Where APP 8.1 applies and the APPs do not otherwise reach the recipient, an act of the overseas recipient that would breach the APPs “is taken, for the purposes of this Act: (a) to have been done, or engaged in, by the APP entity; and (b) to be a breach of those Australian Privacy Principles by the APP entity.” Read plainly: your vendor’s offshore hop becomes your breach.

APP 8.2 then lists exceptions. The one most often relevant commercially is 8.2(a): the entity reasonably believes the recipient is “subject to a law, or binding scheme, that has the effect of protecting the information in a way that, overall, is at least substantially similar to the way in which the Australian Privacy Principles protect the information”, with accessible enforcement mechanisms. Others cover express informed consent (8.2(b)), disclosure required or authorised by Australian law (8.2(c)), a permitted general situation (8.2(d)), two agency-only limbs (8.2(e) and (f)), and 8.2(aa), which points to subclause 8.3. Ask which limb, if any, the vendor relies on, and for the basis in the contract rather than an email. Our guide to AI data sovereignty in Australia covers the wider position, including the automated decision-making transparency obligation.

Foreign jurisdiction, stated precisely

The CLOUD Act point is usually made too loudly. 18 U.S.C. § 2713 provides that a provider of electronic communication service or remote computing service must preserve, back up or disclose communications and records in its “possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States” (govinfo.gov, US Code 2023 edition). The geography of the disk is not the operative test; corporate control is.

The same chapter contains a limit rarely mentioned alongside it. Under 18 U.S.C. § 2703(h)(2)(A) a provider may move to modify or quash legal process where it reasonably believes the subscriber “is not a United States person and does not reside in the United States” and that disclosure “would create a material risk that the provider would violate the laws of a qualifying foreign government” — a term § 2703(h)(1)(A) confines to a government with an executive agreement in force under § 2523. The motion must be filed “not later than 14 days” after service, absent agreement or an extension. The practical buyer question is narrow: which legal entity, incorporated where, controls the keys and the data, and does the contract commit them to notify you of compelled disclosure where law permits?

IRAP and the Hosting Certification Framework are narrower than they sound

Government-adjacent buyers see IRAP badges constantly. The Australian Signals Directorate (ASD) is direct about what IRAP is not. Under the heading “What IRAP does not do” on cyber.gov.au, ASD states: “IRAP Assessors do not accredit, certify, endorse or register systems on behalf of ASD. The scope of a security assessment will generally not cover all ISM security controls and a completed security assessment does not inherently imply that a system is compliant with the tested security controls.” The same page notes the Cloud Services Certification Program “ceased on 2 March 2020”. The artefact is not the badge — it is the assessment report or letter of completion, with its scope and date.

The Hosting Certification Framework is a different instrument. It states that “all sensitive government data, Whole-of-Government systems and systems rated at the classification level of PROTECTED must be hosted using certified services” — an obligation attaching to government customers and their hosting providers, not a general commercial quality mark. Two current facts: responsibility transferred from the Digital Transformation Agency to the Department of Home Affairs on 1 May 2023, and the site states the Department “will pause the HCF Certification registration of prospective service providers and HCF Certified providers seeking supplementary assessment effective from 3 November 2025 until HCF reforms have been completed”, with existing certified providers unaffected (checked 4 September 2026).

The audit table

Claim you might read What it does not rule out Artefact to ask for
“All data stays in Australia” Inference, ASR and TTS calls leaving the country mid-call; telemetry egress Production endpoint hostname or model ID for each of ASR, LLM and TTS, plus the routing policy
“Australian data sovereignty” Backups replicated to a second geography; offshore support access Backup destination region and retention period; countries from which staff can read a transcript
“Processed and stored on Australian soil” A multi-region or “APAC” boundary that includes Singapore, Tokyo or Mumbai The exact region code, and confirmation the profile is single-region rather than geographic or global
“Hosted in Australian data centres” Third-party inference APIs called out from those data centres Subprocessor list with each subprocessor’s processing region and purpose
“Enterprise-grade, IRAP-assessed” A narrow scope; an old assessment; no ASD certification, because ASD does not issue one The assessment report or letter of completion, with scope, ISM controls tested and date
“We don’t train on your data” Retention for abuse monitoring in another region; human review The retention clause, the abuse-monitoring region, and any zero-data-retention amendment
“Encrypted in transit and at rest” Everything about location — encryption says nothing about jurisdiction Key custody: who holds the KMS key, in which region, and whether you can revoke it
“Compliant with the Privacy Act” Reliance on an APP 8.2 exception you have not been told about The clause implementing APP 8.1 reasonable steps, and which 8.2 limb (if any) is relied on

One artefact outweighs the rest: an inference-location log. The AWS cross-Region inference page states: “CloudTrail logs all cross-Region inference requests in your source Region. Look for the additionalEventData.inferenceRegion field to identify where requests were processed.” Ask your vendor for a sample of that field, or its platform equivalent, covering a week of your traffic. A vendor who can produce it has answered the question; one who cannot has told you something too.

Apply the same test to Zian

An audit that exempts its author is advertising. Zian AI is in partnership-application beta. As at 4 September 2026 we do not publish a named cloud region, a subprocessor list with each subprocessor’s processing region, or a statement of where speech recognition, text-to-speech and language model inference run for a given deployment; https://zian.ai/subprocessors/ returns 404, checked 4 September 2026. Zian holds no SOC 2, ISO/IEC 27001 or HIPAA certification of its own.

So run the table against us: ask for the region codes, which components are single-region and which sit behind a multi-region endpoint, the backup destination, the support-access jurisdictions, and which APP 8.2 limb (if any) we would rely on. If any answer is a marketing sentence rather than a region code or a document, that is a finding — against us as much as against anyone else. Our voice AI vendor security questionnaire is the longer form of the same exercise, and you can Apply For Partnership to put it to us directly.

Frequently asked questions

Is “hosted in Australia” a meaningless claim?

No — it is a true but partial claim. It usually describes where the vendor’s application servers and primary datastore run. It does not, on its own, describe where model inference happens, where backups land, or which countries support staff sit in. Treat it as one answer out of six.

What single question exposes the gap fastest?

“For a live call, name the region for the speech-to-text endpoint, the model inference endpoint and the text-to-speech endpoint.” Storage questions get confident answers. That one separates vendors who configured residency deliberately from vendors who assumed it.

Does APP 8 ban sending data overseas?

No. APP 8.1 requires reasonable steps to ensure the overseas recipient does not breach the APPs, and APP 8.2 lists exceptions — including where the recipient is subject to a substantially similar law or binding scheme, or where the individual has been expressly informed and consents. Section 16C then makes the disclosing entity accountable for the recipient’s breaches. See the OAIC’s APP guidelines chapter 8.

Does an IRAP assessment mean a platform is government-approved?

No. ASD states on cyber.gov.au that IRAP assessors “do not accredit, certify, endorse or register systems on behalf of ASD”, and that a completed assessment “does not inherently imply that a system is compliant with the tested security controls”. Ask for the report and check its scope and date.

Are Australian cloud regions enough on their own?

Only if every service you use is available in the specific region and pinned to it. On the AWS general reference endpoints page, Amazon Transcribe lists ap-southeast-2 (Sydney) endpoints for both batch and streaming, but ap-southeast-4 (Melbourne) appears in neither table, checked 4 September 2026. Availability is per-service and per-region, not per-country.

What about the US CLOUD Act?

18 U.S.C. § 2713 reaches data in a US provider’s “possession, custody, or control” regardless of where it is stored, so storage location alone does not settle jurisdiction. Section 2703(h) gives providers a route to move to quash within 14 days in defined circumstances. The buyer’s question is which legal entity controls the data and keys, and what the contract says about notification of compelled disclosure.

What should a good vendor answer look like?

A table: component, provider, region code, single-region or multi-region, retention, and whether personal information is present. Dated, attached to the contract as a schedule, and refreshed when the architecture changes. Anything shorter is a summary of a table that may not exist.

Residency is not a badge. It is a set of configuration decisions that leave evidence. If a vendor cannot produce a region code, a subprocessor list and an inference-location log, the honest reading is that the answer is unknown rather than known-and-good — and under s 16C, unknown is your risk. If you want that conversation with us, including the parts where our answer today is “we do not publish that”, Apply For Partnership.

Related Blogs

Related from Zian AI