Remix.run Logo
johnbarron 11 hours ago

It just not about AWS being some "trusted intermediary"... it's that the model runs inside the customer own AWS account under a different contract. AWS explicitly states inputs/outputs are not shared with model providers and are not used to train base models [1]

And for OpenAI, there is a May 2025 preservation order in NYT v. OpenAI. The court is forcing OpenAI to retain ChatGPT output logs indefinitely, including chats users have deleted that would normally be purged within 30 days [2]. That makes it a non starter for HIPAA/GDPR bound orgs.

[1] https://aws.amazon.com/bedrock/faqs/

[2] https://openai.com/index/response-to-nyt-data-demands/

hn_throwaway_99 11 hours ago | parent [-]

I'm confused, your own #2 link says that Open AI is not bound to store output logs indefinitely going forward:

> Update on October 22, 2025:

> After months of litigation, we are no longer under a legal order to retain consumer ChatGPT and API content indefinitely. Our obligations under the earlier order ended on September 26, 2025.

> We’ve returned to our standard data retention practices :

> Deleted ChatGPT conversations and Temporary Chats will be automatically deleted from our systems within 30 days (opens in a new window).

> API data will also be automatically deleted after 30 days.