Skip to main content

We use cookies to improve your experience and measure traffic. Decline to opt out of analytics and advertising cookies. Cookie preferences

For the person who has to answer the risk committee, not sell to it

Sovereign AI for Australian Business: The Questions Procurement Actually Asks

Somewhere between the pilot that worked and the rollout that was supposed to follow sits a document with about twenty questions on it, sent by risk, legal or procurement. Where is the data processed. Who owns the provider. Can a foreign court compel disclosure. Do they train on our content. What happens if we want out. Most AI projects that stall in Australian organisations stall here, and they stall because nobody prepared an answer that survives a second question.

This page is written for the person answering, not the person selling. It sets out what each question is really testing, what a defensible answer looks like, where the honest answer is that you cannot have what is being asked for, and how to tell the difference between sovereign AI as a national capability question and sovereign AI as a marketing word. We will also state our own boundary plainly: we deliver AI inside the tenancy you already own, configured to the residency your provider actually commits to, with the terms read rather than summarised. We do not rack hardware, host GPUs or operate model serving infrastructure of any kind.

Realistic ROI

Six themes
Cover almost every AI question in a vendor review
Location, jurisdiction, training and retention, access control, assurance evidence, and exit. Prepare those and the questionnaire mostly answers itself
APP 8
Governs cross border disclosure of personal information
APP 8.1 requires reasonable steps before you disclose overseas, and section 16C of the Privacy Act then treats a recipient breach as though your organisation had committed it
In writing
Is the only form of answer procurement can use
A verbal assurance from a vendor cannot be attached to a risk register entry or shown to an auditor eighteen months later
A clear no
Beats a hedged yes every time
An inability disclosed early costs a deal occasionally; a hedged yes discovered at contract stage costs the relationship and the reference

Four Things to Understand Before You Answer Anything

Procurement questions look technical. Most of them are accountability questions wearing technical clothes.

Procurement is protecting accountability it cannot delegate

When a risk team asks where the data goes, they are not being obstructive and they are usually not worried about the specific data centre. They are working out what the organisation remains answerable for after the contract is signed, because under Australian privacy law and under most of the obligations inherited from large customers, you stay accountable for information you hand to someone else. That is why vague answers make them dig harder. Give them the specific service, the specific commitment, the date and the document, and the conversation ends. Give them a reassuring paragraph and it escalates.

Residency, sovereignty and sovereign AI are three different answers

Data residency is where the content physically sits. It is achievable in Australia, but it is platform specific and it splits again into content at rest and prompts in flight. Checked against vendor documentation in August 2026: Microsoft lists Australia among the countries covered by its Advanced Data Residency add on for Microsoft 365 and Copilot, while also telling customers outside the EU that their queries may be processed in the US, the EU or other regions. Google Workspace data regions are the United States or Europe only, with no Australian option. So never write that your platform keeps data in Australia without naming the platform, the service and the setting. Data sovereignty is a different question again: which legal system can compel a provider to produce that content, which follows the provider’s corporate structure rather than the location of the disk. Sovereign AI is a third thing: domestic control of the model weights, the training infrastructure and the supply chain. Answer each one separately and say which risk each closes.

Training and retention terms are the fastest real win

The concern underneath a great deal of sovereignty language is simply this: will our material end up improving a product that our competitor also uses. That is closed by a contract clause, not by a data centre, and it is the cheapest control on the list. Checked in August 2026, the three mainstream commercial offerings all say no in their own documentation: Anthropic’s commercial terms state that it may not train models on customer content, OpenAI states that data sent to its API is not used to train its models unless you opt in, and Microsoft states that Copilot prompts, responses and data reached through Microsoft Graph are not used to train foundation models. The real differences sit in retention and human review rather than in training. OpenAI keeps abuse monitoring logs for up to thirty days by default unless you are approved otherwise, and Anthropic’s commercial default is to retain data indefinitely until you set a retention period. Get the clause, read the carve outs, set the retention deliberately, and attach the document to the risk register.

Some of what gets asked for cannot be bought, and saying so is the answer

A questionnaire will sometimes ask for guarantees no provider can give: absolute immunity from foreign legal process, a commitment that a model will never produce an incorrect statement, or sovereign control of a model developed overseas. The correct response is to name the limit, describe the compensating control, and let the organisation make a risk decision with accurate information. Every vendor who instead answers yes to all of it is storing up a much worse conversation for later. We would rather lose a deal at the questionnaire than be the reason a risk register is wrong.

The Six Themes Behind Almost Every AI Questionnaire

Prepare an evidenced answer for each of these once, and most reviews become an afternoon rather than a quarter.

Named region, named service, named setting, dated

Where it is processed

The answer is not the vendor’s country of operation. It is the specific service, the specific region, the specific setting and the date you verified it against the provider’s published position. Split storage from processing, because reviewers do. Azure states the distinction plainly: data at rest stays in the chosen geography, but inference under a Global deployment may run in any Azure region, under a Data Zone deployment stays within the US, EU or Asia Pacific zone, and only under a single region deployment stays in the deployment region. Asia Pacific is not Australia. Residency commitments are also made service by service, and new capability tends to reach the globally routed options first. State which workloads are covered, state which are not, and record the source. An answer of the form "our provider has an Australian presence" reads to an experienced reviewer as an answer that has not been checked.

Honest, with the residual named

Whose law can reach it

Set out who owns the provider, where it is incorporated, and which subprocessors touch the data and where they operate. Then state the residual risk plainly: a globally owned provider may be subject to legal process in its home jurisdiction regardless of where the data sits. For most commercial organisations that is an acceptable disclosed risk. For defence adjacent work or certain regulated datasets it may not be, and that determination belongs with your legal advisers rather than with any implementation partner including us.

Quoted from the agreement

Training, retention and human review

Cite the clause that excludes your content from foundation model training, state the retention period for content held for abuse or safety monitoring, say whether human reviewers can access flagged content, and note whether preview features sit under different terms. Attach the data processing addendum. This is the theme where a precise answer does the most work, because it is the one most stakeholders are actually anxious about even when they phrase it as sovereignty.

Identity based and testable

Who can see what

Access runs through the identity provider you already use, with existing groups, conditional access and multi factor requirements. Where the system reads documents, state that retrieval inherits the permissions on those documents so a user cannot obtain content they could not already open, and describe how that was tested rather than asserting it. Reviewers respond well to a described test with a low privilege account, because it is the only part of the answer they can imagine verifying themselves.

Certificates plus your own controls

Assurance and evidence

Provider certifications are useful and insufficient on their own, because they attest to the provider’s processes rather than to your configuration. Pair them with your own evidence: the region setting, the retention configuration, the audit log retention window, the results of your permission test and the date of your last review. A management system standard for AI now exists, ISO/IEC 42001, published in 2023 and already appearing in the compliance offerings of the large providers. It is worth understanding if you sell to enterprise or government, though for most mid sized firms a documented control set beats a certification project.

The question people forget

Exit and continuity

What happens if the provider changes terms, restricts a capability, raises prices sharply or exits. This is the concern that usually sits under sovereignty language, and the control for it is architecture rather than geography. Keep source content and business logic in forms you own, avoid building irreplaceable process on a single proprietary feature, and be able to state what a switch would cost in time and money. A reviewer who gets a real answer here tends to relax about several of the earlier questions.

Common Questions, Weak Answers and Answers That Hold Up

TaskTraditionalAn answer that survives scrutinyNotes
Where is our data stored?Our provider is a major cloud with Australian operationsNamed service, Australian region, verified on a stated dateCoverage is per service, and where it is stored is not where it is processed.
Can a foreign government access it?No, it is stored in AustraliaOwnership, jurisdiction and the residual risk statedThe wrong answer here is the one most likely to unravel later. Name the limit.
Do they train on our content?Their website says they do notClause cited from the agreement, carve outs notedMarketing pages change without notice. The addendum is what an auditor reads.
Is this sovereign AI?Yes, it runs in AustraliaNo. It is Australian residency, and here is why that differsAnswering yes to this invites the follow up question you cannot answer.
Who can see the outputs?Only authorised usersIdentity groups named, permission test describedA described test beats an assertion, because the reviewer can picture repeating it.
How long is data retained?Per the vendor defaultConfigured value, plus audit log retention windowDefaults suit the product, not your disposal schedule. Some default to indefinite.
What if we want to leave?We would migrateWhat we own, what we would rebuild, rough costThe question sovereignty language is usually really asking. Answer it directly.
What could go wrong?Nothing, it is enterprise gradeNamed failure modes and the controls for eachA vendor who names risks is more credible than one who claims there are none.

How Australian Organisations Get This Wrong

Answering the questionnaire the day it arrives

A rushed response written by whoever is free produces vague answers, which produces follow up questions, which produces a second round and a delay of weeks. Build the evidence pack once, before you need it: the residency position per workload with dates, the data processing addendum, the subprocessor list, your configuration settings, your permission test results and your exit position. Reuse it for every review. The first pack takes a few days and every subsequent questionnaire takes an hour.

Letting a vendor answer on your behalf without checking

Vendors answer their own questions accurately and your questions optimistically, and the accountability for what goes into your risk register is yours, not theirs. Read what they wrote, check the residency claim against the provider’s published position for the specific service, and verify that the training exclusion they cite appears in your agreement rather than in a general marketing statement. Where a vendor cannot produce a document, record that as the answer. It is a finding, and findings are what the process exists to surface.

Buying a specialised sovereign arrangement for ordinary workloads

Domestically restricted arrangements exist in Australia and they are real. They also carry a capability lag the providers document themselves: on Azure, for instance, new models reach the globally routed deployment types first and the single region deployment types last, with no guaranteed availability date. We will not quote you a price differential against the mainstream products, because no published comparison supports one and inventing a number would be worse than saying nothing. What we will say is that these arrangements are correct for a narrow band of buyers with genuine jurisdictional obligations, and that applying the same constraint to public information or routine internal documents buys delay without closing a real risk. Classify your workloads by sensitivity before you shop, because the genuinely sensitive slice is almost always smaller than the total.

Confusing certification with configuration

A provider’s certifications attest to their processes and say nothing about how your tenancy is set up. An organisation can hold every relevant certificate in its supplier file and still have retention set to indefinite, sharing wide open and no audit log retention worth the name. Reviewers who only collect certificates miss this entirely. Pair the provider evidence with your own configuration evidence, and make the configuration review recurring rather than a one off at go live, because settings drift as people solve problems.

Treating the Privacy Act analysis as an IT deliverable

Whether you have a lawful basis, whether your privacy notice reflects what actually happens, how you handle access and correction when information sits inside an index, and how cross border disclosure obligations apply are legal questions with technical inputs. They are not answered by a diagram of the architecture. Get the analysis done by someone qualified and keep it current, because the ground has already moved: the Privacy and Other Legislation Amendment Act 2024 amended the Act, and the statutory tort for serious invasions of privacy commenced on 10 June 2025. A 2021 assessment is not a current one. Give the technical team the specific constraints that fall out of the advice rather than asking them to interpret the legislation.

Never testing the controls you claimed

The most uncomfortable moment in an AI assurance review is when someone asks to see the permission test and there has never been one. Pick a low privilege account, pick content it must not reach, and try to extract that content through the interface including indirectly. Revoke access to an indexed document and measure how long the change takes to take effect. Write both results down with dates. Controls you have asserted but never exercised are the ones that turn out not to work, and finding that out yourself is enormously cheaper than the alternative.

How Yes AI Supports Procurement Conversations

We build the evidence pack, not a reassurance paragraph

Residency position per workload with sources and dates, the data processing terms and their carve outs, the subprocessor position, your configuration settings, permission test results and an exit statement. Written so your risk team can use it directly rather than translate it.

Claims verified against the source, including our own

We read the provider’s current published position for the specific service rather than answering from memory or from a slide deck, and we date what we relied on. If a claim we made six months ago has been overtaken by a product change, we would rather tell you than let it sit in your register.

A clear line about what we do not do

We do not rack hardware, host GPUs or operate model serving infrastructure, and we will not describe running a foreign developed model in an Australian region as sovereign AI. If your requirement genuinely is domestic model hosting, that is an infrastructure engagement with a different kind of partner, and we will say so early.

Honest advice, including when the answer is no

Some things a questionnaire asks for cannot be provided by anyone, and some projects should not proceed in the form they were scoped. We will name the limit and the residual risk rather than write a hedged yes, because a risk register that is wrong is worse for you than a project that is smaller.

From Stalled Review to a Signed Position

Five steps. Done once, the pack serves every subsequent review.

Read the questions behind the questions

We work through the actual questionnaire or risk register entries and identify which of the six themes each item is testing, because a surprising number of questions are duplicates phrased differently, and a few are asking something nobody has noticed.

Classify the data in scope

Public, internal, and material that would cause real harm if disclosed. The control set and the cost follow directly from this, and it is the step that stops a whole organisation being governed at the standard of its most sensitive dataset.

Verify the position with sources

Published residency statements per service, data processing terms with carve outs read rather than skimmed, subprocessor list, and your current configuration as it stands today rather than as documented in an old handover.

Test what you intend to claim

A low privilege account attempting to reach restricted content, a revoked access propagation check, and confirmation of the audit log retention window. Results written down with dates so the claim is evidenced rather than asserted.

Write the pack and set a review cycle

One document your risk team can attach to a register, with a named owner, a stated review trigger on major product changes, and the residual risks named rather than buried. Reused for every future questionnaire.

FAQ

Get the Answer Ready Before the Questionnaire Arrives

Book a call. We work through the six themes against your actual deployment, verify the position with sources and dates, and leave you with a pack your risk team can sign. Priced after scoping.

All discussions held in confidence. Australian-based consultants.