AWS Bedrock or Vertex AI for Claude in the EU?
Both AWS Bedrock and Google Vertex AI offer EU storage for Claude, with the hyperscaler as data processor and Anthropic as subprocessor, using customer-controlled keys. Bedrock offers direct EU regions and EU cross-region profiles; Vertex's EU path relies on multi-region, which isn't the same as a single member-state region under strict requirements.
You’ve landed on wanting to use Claude. Good – that’s half the decision made. The other half is where the model runs: via AWS Bedrock or Google Vertex AI. For an EU company with data protection requirements, that’s not a detail – it’s what determines how simple your compliance documentation ends up being.
What’s the same
Start with the similarities, since they’re bigger than you’d think. On both platforms, the setup is fundamentally the same:
- The cloud provider is the data processor, and Anthropic is the subprocessor. So you have a Data Processing Agreement with the hyperscaler, not directly with the model company.
- EU storage is possible on both.
- You control the encryption keys yourself – with AWS KMS on Bedrock and Google CMEK on Vertex.
If the comparison ended here, the choice would be purely a matter of taste. But it doesn’t end here.
What differs: regional geography
The most important difference is about how “EU” is actually realized.
Bedrock combines two things: direct EU regions – including Stockholm – and EU cross-region profiles that keep traffic within the geography even when it’s distributed for capacity. So you can point to a specific member-state region.
Vertex’s EU path instead relies on a multi-region endpoint. And here’s a distinction auditors care about: multi-region isn’t the same as a single member-state region. If your requirement is strict single-region – that data must stay in one specific country – a multi-region solution isn’t enough to check that box without qualification.
| Aspect | How it differs |
|---|---|
| EU regions | Bedrock: direct regions (incl. Stockholm) + cross-region profiles within the EU |
| Vertex EU path | Relies on a multi-region endpoint – not a single member-state region |
| Key control | Bedrock: AWS KMS. Vertex: Google CMEK |
| Abuse-detection storage | Bedrock: follows the destination region |
The detail auditors ask about
Abuse detection – the process that catches disallowed use – also stores data somewhere. On Bedrock, that storage follows the destination region, according to the documentation. That means if your traffic goes to an EU region, that process does too.
It sounds like a technicality, but it’s exactly the kind of question that comes up in an audit: “where does the data from the abuse check end up?” Having a clear answer saves time, and it’s a point to verify against current documentation before the contract is signed.
A related pitfall is assuming the choice of model itself decides where data ends up. It doesn’t – the configuration does. On both platforms you have to actively point region and profile correctly, and verify that surrounding processes like logging and abuse detection follow along. A misconfigured EU setup that happens to route traffic outside the geography looks the same day to day but fails in an audit. Provability sits in the settings, not in the model’s name.
What actually decides it
Here’s the uncomfortable truth: the model list is rarely what should decide it. When both platforms give you Claude with EU storage and your own keys, the practical factors weigh heavier:
- Which cloud agreement do you already have? Adding a service where you already have contracts and routines is cheaper than opening a new vendor relationship.
- What does your IAM and access governance look like? The platform you already master produces fewer misconfigurations.
- Which audit tools do you use? Logging and traceability should fit into what you already audit.
In practice, the cloud provider you already have maturity in often wins. It’s not an exciting answer, but it’s what holds up in operations and audit.
One concrete way to break the deadlock: ask where your logs already end up and who can already read them. If you’ve built up permissions, alerts, and audit routines in one cloud, the other means rebuilding all of that in parallel – and every new place data passes through is another line in your compliance documentation. If your residency requirement is also strict single-region, that tilts toward Bedrock, which can point to a specific member-state region; if the requirement is softer, the practical factors weigh heavier. So let the need for provable geography and your existing maturity decide, not whichever platform happens to mention Claude first.
The region and model matrix also changes often at both providers, so treat this comparison as perishable and verify current documentation before deciding. Want help weighing your existing contracts and requirements against each other? Read about our AI services or get in touch with your current situation, and we’ll go through it together.
Frequently asked questions
What do Bedrock and Vertex have in common for Claude in the EU?
Both offer storage within the EU, with the cloud provider as data processor and Anthropic as subprocessor. Both support customer-controlled encryption keys – AWS via KMS and Google via CMEK. At the overall level the setups look alike; the differences lie in regional geography and the details.
What's the difference between single-region and multi-region?
Bedrock offers direct EU regions, including Stockholm, plus cross-region profiles that keep traffic within the EU. Vertex's EU path relies on a multi-region endpoint. If your requirement is strict single-region in a specific member state, multi-region isn't the same thing, and that needs to be documented.
Where is abuse-detection data stored?
On Bedrock, abuse-detection storage follows the destination region, according to the documentation. It's a detail auditors often ask about, since it decides whether that process also stays within the EU. Verify current documentation, since these terms change.
Which choice is right for us?
The practical factors often outweigh the model list: which cloud agreement you already have, how your IAM and access governance look, and which audit tools you use. Placing Claude where you already have maturity and a contract reduces both risk and work.
Can we trust the region and model matrix to stay stable?
No – models, regions, and profiles change often at both providers. Treat any comparison as perishable and verify against current documentation before deciding, especially when a strict residency requirement is the basis for the choice.