OpenAI finally lets businesses park their data in 10 regions
Curated by the Inblix editorial team
OpenAI is making a long-awaited concession to enterprise compliance teams: data residency is now widely available for business customers in a slew of key markets. If you’re on ChatGPT Enterprise, ChatGPT Edu, or an approved API plan, you can now pin your customer content at rest to a specific geographic region rather than trusting it to float around in OpenAI’s default infrastructure. The initial list covers Europe, the UK, the US, Canada, Japan, South Korea, Singapore, India, Australia, and the UAE, with more regions promised down the line.
This isn’t just a cosmetic checkbox. For API customers with advanced data controls enabled, the setup means model requests and responses aren’t stored at rest on OpenAI’s servers at all. They’re handled in-region and then discarded. ChatGPT workspaces get a broader sweep: conversations, uploaded files, custom GPTs, and even image generation artifacts all stay put in the selected region. It’s a meaningful upgrade for anyone who’s had legal breathing down their neck about where corporate data sleeps.
OpenAI is layering this on top of its existing security stack—AES-256 encryption at rest, TLS 1.2+ in transit, plus the option to bring your own encryption keys through Enterprise Key Management. The company is also keen to remind everyone that it doesn’t train models on business data by default, and it’s holding the usual compliance badges: SOC 2 Type 2, ISO 27001, GDPR alignment, the works. That’s table stakes for enterprise AI vendors at this point, but pairing it with data residency closes a gap that’s been annoying procurement teams for over a year.
What’s still unsaid is how this affects latency or inference speed when you’re routing to a specific region instead of the nearest available compute. OpenAI isn’t publishing performance benchmarks by region yet, and for API customers pushing high-throughput workloads, that could matter more than where the data sits at rest. The real test will be whether regional pinning becomes a seamless default or a tradeoff that engineering teams have to negotiate with their compliance counterparts.
💡 Key Takeaways
- Data residency now covers 10 regions, letting ChatGPT Enterprise, Edu, and API customers store content at rest within a chosen jurisdiction.
- API customers with advanced data controls can process requests in-region without OpenAI storing model inputs or outputs on its servers at all.
- OpenAI's enterprise security stack already includes AES-256 encryption, TLS 1.2+, and SOC 2/ISO 27001 certification—data residency fills a compliance gap rather than a security one.
- The announcement leaves latency and performance implications unaddressed, which could become a sticking point for high-volume API users as adoption scales.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.