AI model routing: which vendor sees your data
Whichever one the routing layer picks. Every model call decides which provider sees which data, and a router that weighs only cost will eventually send regulated data somewhere convenient.
By Harinderpal Hanspal on October 2026. Updated October 2026
Whichever one the routing layer picks, and most buyers never ask where that layer is. Every model call is a decision about which provider sees which data.
"Cheapest capable model" and "a model this data may legally visit" are different filters. A router that knows only the first will eventually send regulated data somewhere convenient.
Treated properly, routing policy makes three decisions explicit that organizations usually make without noticing:
- Which providers exist at all. This should be an allowlist, not a collection of API keys scattered through configuration files.
- Which data classes may reach which providers, checked at dispatch for each request.
- What happens when the preferred model is down. A fallback chosen during an outage inherits none of the review the primary model received.
There is a fast test for any system. Search the code for provider software development kits (SDKs). If a component imports one outside the routing layer, the architecture diagram is wrong about where data can go.
Ask a vendor three questions. Can any component reach a model provider without passing the shared routing layer? Does routing policy know about data classes, or only about price? Who reviewed the fallback chain, and when?
Go deeper: Open or closed weights: settle the data policy before the model lays out the data-policy questions to settle before a model is shortlisted, Governing agents in production puts routing among the controls that belong below the agent, and how we score agentic AI covers governance readiness.