Skip to main content

AI Model Governance Matrix

Source of truth for which model may process which class of data, and the third-party-ICT register for the LiteLLM gateway. Feeds EU AI Act (technical documentation + risk classification) and DORA (register of ICT third parties

  • concentration/exit analysis) and GDPR/ACPR (data residency).

Stories: platform-backlog #301 (this matrix) + #302 (data classes). Enforcement (tag-based routing + PII pre-check) is #305.

1. Data classification scheme (#302)​

ClassMeaningExamples (ktayl insurance IS)
P0 β€” PublicNon-sensitive, publicly shareablemarketing copy, public docs, generic Q&A
P1 β€” InternalInternal business, no personal datainternal procedures, non-personal analytics
P2 β€” ConfidentialSensitive business, limited personal datacontract terms, aggregated claims data
P3 β€” RestrictedPersonal data / regulated (DORA/ACPR scope)policyholder PII, claims dossiers, health/financial data

Golden rule: a request may only be routed to a model whose max allowed class β‰₯ the request's class. PII detected (Presidio) forces the request to the on-cluster tier regardless of the declared class.

2. Per-provider governance matrix (#301)​

Tier / ProviderModels in the gatewayJurisdictionData terms (training / residency)Max data classCost
On-cluster (vLLM + agents) 🏠phi3-financial, phi3-financial-ft, research-agent, deep-research-agentπŸ‡«πŸ‡· self-hosted (minicloud)data never leaves the cluster; no external call; no trainingP3 β€” Restricted βœ…free
Mistral πŸ‡ͺπŸ‡Ίmistral-large, mistral-small, mistral-embedπŸ‡«πŸ‡· France / EUAPI data not used for training; EU/GDPR-alignedP2 β€” Confidentialpaid (cheap)
AWS Bedrock (E1, EU) πŸ‡ͺπŸ‡ΊClaude/Llama/Mistral via bedrock/ (region eu-west-1)πŸ‡ͺπŸ‡Ί EUcontractual no-training + EU residencyP2 β€” Confidentialtokens
Azure OpenAI (E2, EU) πŸ‡ͺπŸ‡ΊGPT-4o/Claude via azure/ (EU region)πŸ‡ͺπŸ‡Ί EUcontractual no-training + EU residencyP2 β€” Confidentialtokens
OpenAI πŸ‡ΊπŸ‡Έgpt-4o, gpt-4o-mini, text-embedding-3-smallπŸ‡ΊπŸ‡Έ USAPI not trained (since 2023); US CLOUD Act (no EU residency)P1 β€” Internalpaid
Anthropic πŸ‡ΊπŸ‡Έclaude-sonnet, claude-haikuπŸ‡ΊπŸ‡Έ USAPI not trained; US jurisdictionP1 β€” Internalpaid
Google Gemini πŸ‡ΊπŸ‡Έgemini-2.0-flash, gemini-1.5-proπŸ‡ΊπŸ‡Έ USpaid tier not trained; free tier MAY beP1 β€” Internal (paid only)paid
NVIDIA NIM πŸ‡ΊπŸ‡Έnvidia-nemotron-70b, nvidia-llama-8b, nvidia-deepseek-r1πŸ‡ΊπŸ‡Έ US (build.nvidia.com)free inference tier β€” terms uncertainP0 β€” Publicfree tier
Groq πŸ‡ΊπŸ‡Έgroq-fallback (+ phi3-financial route)πŸ‡ΊπŸ‡Έ USfast inference; enterprise terms less clearP0 β€” Publicfree/cheap
HuggingFace (router) πŸ‡ΊπŸ‡Έhf-qwen, hf-gemma (featherless-ai router)πŸ‡ΊπŸ‡Έ US (3rd-party router)third-party routing, terms uncertainP0 β€” Publicpaid
Ollama Cloud 🌐ollama-cloud (gpt-oss:120b, 3-key round-robin)US-ish (new service)terms uncertain (new provider)P0 β€” Publictokens
DeepSeek πŸ‡¨πŸ‡³ πŸ”΄deepseek-chat, deepseek-r1:7bπŸ‡¨πŸ‡³ China (PIPL, no GDPR adequacy)πŸ”΄ data-sovereignty riskP0 β€” Public ONLY β€” NEVER PII/regulatedcheap

Nuance β€” DeepSeek via NVIDIA: nvidia-deepseek-r1 runs the DeepSeek model on NVIDIA US infra β†’ data goes to the US, not to China. It's P0 (US free tier), distinct from the direct deepseek-* (β†’ China) which carry the πŸ”΄ CN sovereignty flag.

3. Routing policy (input to #305)​

Request data classAllowed models
P3 β€” Restricted (PII/regulated)on-cluster ONLY (vLLM + agents + mistral-embed… on-cluster embeddings)
P2 β€” Confidentialon-cluster + EU (Mistral, Bedrock-EU, Azure-EU)
P1 β€” Internal+ US enterprise (OpenAI, Anthropic, Gemini-paid)
P0 β€” Publicany, incl. cheap/free (Groq, NVIDIA-free, HF, Ollama Cloud, DeepSeek)

Enforcement (#305, LIVE): each model carries model_info.access_group in the LiteLLM config (onprem/eu/us; untagged = P0-only). A virtual key scoped to models: ["onprem"] can only reach P3-safe on-cluster models, ["eu"] only EU models, etc. (key scoping = #306). Presidio PII masking is default_on globally β†’ PII is masked before any cloud call regardless of class.

Hard blocks: DeepSeek-CN and any "uncertain-terms" free tier are never eligible for P1+. A Presidio PII hit downgrades routing to on-cluster.

4. Compliance mapping​

  • EU AI Act: this matrix is part of the technical documentation. The Retrieva DORA-RAG is limited-risk / transparency-tier (assists, cites sources, human-in-the-loop); the gateway is infrastructure. High-risk use cases (if introduced) must use the on-cluster / EU tier + human oversight + audit (#309).
  • DORA (Reg. EU 2022/2554): each external LLM provider is an ICT third party β€” this table is the register (provider Β· jurisdiction Β· criticality). Watch concentration risk (don't route all critical flows to one US provider) and keep an exit path (the LiteLLM gateway makes provider swap a config change; on-cluster is the fallback).
  • GDPR / ACPR: personal/regulated data (P3) stays on-cluster (data residency + minimisation). EU providers (P2) only with a DPA.

5. Maintenance​

Update this file whenever a model is added/removed in manifests/ai/00-litellm-configmap.yaml. The machine-readable projection (model_info tags per model β†’ tag-based routing) is applied in #305.