There are at least nine "ChatGPT vs Claude vs Gemini" comparison posts already ranking, and they all score the same three things: pricing, context window, and a vague nod to "privacy." None of them ask the questions a CISO actually needs answered before a tool touches a regulated workload — which model is really behind it, whether it can run without an internet connection, and whether the vendor's own jurisdiction is the risk.
This is the scored version of that comparison — the one built on the same framework this site uses to evaluate any AI tool, extended into a full lens: seven axes, thirteen tools, every claim traced to a named, dated source.
The Delfen Lens: seven axes, thirteen tools
Each cell: ● strong · ◐ adequate/mixed · ○ weak or absent · ? vendor doesn't disclose it.
| Tool | Security | OT-fit | Sovereignty | Agnostic | Open-source | Air-gapped | Governability |
|---|---|---|---|---|---|---|---|
| ChatGPT / OpenAI API | ● | ○ | ● | ◐ | ◐ | ○ | ◐ |
| Claude / Anthropic | ● | ○ | ○ | ◐ | ○ | ○ | ◐ |
| Google Gemini | ● | ○ | ◐ | ◐ | ◐ | ○ | ◐ |
| Microsoft 365 Copilot | ● | ○ | ◐ | ○ | ○ | ○ | ● |
| GitHub Copilot | ◐ | ○ | ? | ○ | ○ | ○ | ◐ |
| Amazon Q | ◐ | ○ | ◐ | ◐ | ? | ○ | ◐ |
| IBM watsonx.ai | ● | ◐ | ? | ● | ● | ● | ◐ |
| Meta Llama | ○ | ◐ | ◐ | ● | ◐ | ● | ○ |
| Mistral | ○ | ◐ | ● | ● | ◐ | ◐ | ○ |
| DeepSeek | ○ | ○ | ○ | ◐ | ● | ○ | ○ |
| Perplexity Enterprise | ◐ | ○ | ○ | ◐ | ○ | ○ | ● |
| Cohere | ● | ◐ | ◐ | ● | ◐ | ● | ○ |
| Salesforce Agentforce | ● | ○ | ● | ◐ | ○ | ○ | ● |
Three patterns in that table will surprise you more than the rest. Here's why they matter.
Surprise one: "open-source" is not the AI Act split you'd expect
You'd assume the frontier labs are uniformly closed and the open-weight players are uniformly open. Neither half is true.
OpenAI and Google both quietly shipped an open sibling to their closed flagship. OpenAI released gpt-oss-120b and gpt-oss-20b under Apache 2.0 in August 2025 — its first open-weight release since GPT-2. Google's Gemma line reached genuine Apache 2.0 with Gemma 4; the earlier Gemma 1–3 generations shipped under a more restrictive custom license, so Google's openness commitment is newer and less consistent than it looks at first glance. (Gemma is a separate model family from the Gemini product in the table above — same company, different license terms.) Anthropic is the only one of the three frontier labs with no open-weight model at any tier — a real, sharp differentiator, not a rounding error.
On the "open" side of the table, the honest picture is messier than the marketing. Meta's Llama ships under a custom Community License, not an OSI-approved one — it includes a clause requiring companies over 700 million monthly active users to request a separate license, and, more surprisingly, Llama 3.2's multimodal weights specifically are not licensed to individuals domiciled in, or companies headquartered in, the EU (the text-only variants are unaffected). Cohere's open-weight Command models are CC-BY-NC-4.0 — open-weight, genuinely inspectable, but non-commercial, which is a meaningfully different thing from open-source. DeepSeek's R1 is cleanly MIT-licensed; DeepSeek-V3's code is MIT but its model weights ship under a separate DeepSeek Model License — permissive, but not the same license, and worth knowing before you cite "DeepSeek is MIT" as a flat fact.
Surprise two: Claude has the weakest sovereignty story of the group
If you assumed the safety-focused lab would also be the EU-friendliest one, the data says otherwise. Anthropic's own platform documentation states plainly that Claude's workspace data storage is US-only — there is no EU-region option at the direct-vendor level. The only way to get Claude with genuine EU data residency is through a third party: AWS Bedrock (Frankfurt, Ireland, Paris, or Stockholm) or Google Cloud Vertex AI's EU regions.
OpenAI has the most mature direct EU story of the three frontier labs — API customers can select Europe as the data-residency region at project creation, with zero data retention by default. The catch: this can only be set when a project is created, not migrated onto an existing one.
Microsoft 365 Copilot's EU Data Boundary has a carve-out worth knowing before you rely on it. Microsoft's own documentation says so directly, in the very first callout box on the page: "Anthropic models are out of scope for the EU Data Boundary and when available, in-country LLM processing commitments." If your Copilot session happens to route through Anthropic's models, that traffic isn't covered by the boundary you thought applied to the whole product.
Salesforce has the cleanest EU story of all thirteen tools. Its Hyperforce EU Operating Zone stores and processes EU customer data within the EU, with EU-based support and engineering staff, and an architecture explicitly designed to keep data from exiting the region. Mistral backs its sovereignty positioning with real capital — over $830 million in debt financing for a Paris-area data center, plus a further €1.2 billion investment in Sweden for EU capacity — making it the most explicitly "sovereign-first" vendor in the set, by design and by funding.
Surprise three: genuine air-gapped deployment is rarer than every "self-hosted AI" headline implies
Only two of the thirteen tools have a confirmed, vendor-documented path to running fully air-gapped or on-premises as an enterprise product: IBM watsonx (built on Red Hat OpenShift, which supports disconnected/air-gapped configuration, plus a packaged on-prem offering and a VMware Private AI partnership) and Cohere (genuine VPC, on-premises, or dedicated "Model Vault" deployment, where Cohere states it does not receive customer prompts or generations). Every SaaS copilot in this table — ChatGPT, Claude, Gemini, Microsoft 365 Copilot, GitHub Copilot, Amazon Q, Perplexity, Salesforce Agentforce — is cloud-only, full stop.
The open-weight models are a different case: air-gapping them is possible, but the hardware reality varies enormously by size. Meta's small Llama variants (1B/3B) are genuinely confirmed running on a Raspberry Pi 5 via Ollama, at roughly 3–6 tokens per second — real, benchmarked, usable for light interactive tasks. The 70B-class Llama models need a real GPU: a single 48GB+ card at heavy quantization, or multi-GPU setups for full precision. DeepSeek is the case to watch here. Its R1/V3 flagship is 671 billion parameters (37 billion active per token) — enterprise-cluster infrastructure, nowhere near a Pi or a single consumer GPU. The "DeepSeek runs on small hardware" claims circulating online almost always describe much smaller distilled variants built on a different base model entirely — not the flagship the benchmarks are earned on. Don't let a demo of a distilled model stand in for the real thing.
The one to actually worry about: DeepSeek
Every other tool in this table has a business-risk profile — vendor lock-in, an unclear model identity, a governance gap you'd have to build yourself. DeepSeek is different in kind, not just degree.
DeepSeek's own privacy policy states plainly, twice in the document: "we directly collect, process and store your Personal Data in People's Republic of China." As a China-domiciled company, DeepSeek is subject to China's 2017 National Intelligence Law, which requires organizations to support national intelligence work on request — without a requirement to notify the individuals affected.
This isn't a theoretical concern. Italy's data protection authority, the Garante, formally ordered DeepSeek to block its chatbot for Italian users on 30 January 2025, after DeepSeek's operators gave the regulator information judged "totally insufficient" about what data is collected, where it's stored, and on what legal basis. Separately, the cybersecurity firm Feroot Security found code embedded in DeepSeek's web login page linking to CMPassport.com — China Mobile's authentication registry, and China Mobile is barred from operating in the US. Two independent academics, Joel Reardon (University of Calgary) and Serge Egelman (UC Berkeley), verified the code linkage, and the Associated Press covered the finding directly. In fairness: neither Feroot nor the two academics observed an actual data transfer to China Mobile during testing from North America — the finding is about the code's capability, not confirmed active exfiltration in every session.
None of this means DeepSeek's models are bad. R1 and V3 are genuinely capable, and the code license is genuinely permissive. It means the sovereignty and governability columns for DeepSeek in the table above aren't a stylistic choice — they're the honest read of a real regulatory record.
Nobody has DORA or NIS2 in their contract
Search every vendor's public compliance page for "DORA" or "NIS2" by name and you'll come back with nothing — not from OpenAI, not from Anthropic, not from Microsoft, not from any of the thirteen. The best available proxy across the board is ISO 27001 plus SOC 2 plus a GDPR-based Data Processing Agreement. If a vendor's sales team tells you their product is "DORA-compliant" or "NIS2-ready" as a named, contractual fact, ask them to point to the clause — as of this writing, none of them have written it down.
Monday morning
Pick the one axis that actually gates your next AI decision — sovereignty if you're EU-regulated, air-gapped if you're anywhere near OT, governability if your board is asking who's accountable when the tool is wrong — and re-read this table for that column alone. Most vendor conversations start from "which tool is smartest." Start from the axis you can't compromise on, and let that column, not the marketing deck, narrow the list before the demo.
Common questions
Which AI tool is best for regulated industries? There's no single answer — it depends which axis is non-negotiable for you. Salesforce and OpenAI have the strongest direct EU-sovereignty stories; IBM watsonx and Cohere are the only two with genuine air-gapped deployment; Microsoft 365 Copilot has the most mature audit/eDiscovery governance layer. Claude and DeepSeek are the two clearest "know what you're trading off" cases — Claude on sovereignty, DeepSeek on nearly everything.
Can you run Claude or ChatGPT air-gapped, like on a Raspberry Pi?
No — both are closed, API-only models with no self-hosting option. Open-weight models can run air-gapped: Meta's small Llama variants (1B/3B) are confirmed running on a Raspberry Pi 5 at 3–6 tokens per second, and OpenAI's own gpt-oss and Google's Gemma are also genuinely self-hostable, unlike their closed flagships.
Is DeepSeek safe to use in a regulated organisation? Treat it as a real, documented risk, not a hypothetical one. Italy's data protection authority formally blocked it in January 2025, its own privacy policy confirms data storage in China, and independent security researchers found code linking its login page to a China Mobile system barred from US operation. For a regulated or OT environment, this is the one tool on this list that needs a genuine risk conversation before a pilot, not just a Terms of Service review.
Does using an AI tool's paid or enterprise tier stop it from training on your data? Usually yes, but check the specific tier, not just "paid." OpenAI's API and ChatGPT Enterprise/Business/Edu exclude training by default; Anthropic's commercial products do too. GitHub Copilot changed its policy on 24 April 2026 — Free, Pro, and Pro+ tiers now train on interaction data by default (opt-out available), while Business and Enterprise remain excluded. Google's consumer Gemini app trains by default with human review unless you opt out; Workspace and enterprise API tiers are contractually excluded.
Scoring your own shortlist
The seven axes here are a repeatable method, not a one-time ranking — the same lens applies to any tool you're evaluating, including ones not on this list of thirteen. If you're weighing a live decision and want a second, independent read against your organization's specific constraints, that's a conversation, not a pitch.
Sources & further reading
- Introducing gpt-oss — OpenAI, August 2025
- gpt-oss-120b Model Card — OpenAI (Hugging Face), 2025
- Introducing data residency in Europe — OpenAI, 2025
- Data residency for the OpenAI API — OpenAI Help Center, 2025
- OpenAI Trust Portal — OpenAI, 2026
- Data residency — Claude Platform Docs — Anthropic, 2026
- What certifications has Anthropic obtained? — Anthropic Privacy Center, 2026
- Gemma 4: Expanding the Gemmaverse with Apache 2.0 — Google Open Source Blog, 2026
- Gemini Apps Privacy Hub — Google, 2026
- Google Cloud Next 2026: AI agents, A2A protocol, Workspace Studio, and the full-stack bet against OpenAI and Anthropic — TheNextWeb, April 2026
- Compliance certifications and security controls — Google Cloud Documentation, 2026
- Data, Privacy, and Security for Microsoft 365 Copilot — Microsoft Learn, 2026
- Audit logs for Copilot and AI applications — Microsoft Learn, 2026
- Updates to GitHub Copilot interaction data usage policy — The GitHub Blog, March 2026
- Amazon Q Developer service improvement — AWS Documentation, 2026
- Amazon Q Business now available in AWS Europe (Ireland) Region — AWS, March 2025
- Amazon Q Developer is now generally available in the AWS Europe (Frankfurt) Region — AWS, April 2025
- Introducing the IBM Granite 4.1 family of models — IBM Research, 2026
- IBM Expands FedRAMP Portfolio with Authorization of 11 Software Solutions, Including watsonx — IBM Newsroom, April 2026
- Infusing AI into applications using IBM watsonx.ai with Red Hat OpenShift AI — Red Hat Blog, 2025
- IBM and VMware help enterprises adopt generative AI with watsonx on premises — IBM, 2023
- Llama 3.2 Community License Agreement — Meta, 2024
- Llama 3.2 Acceptable Use Policy — Meta, 2024
- How Well Do LLMs Perform on a Raspberry Pi 5? — Stratosphere Laboratory, June 2025
- Raspberry Pi OS 2024-10-22 benchmark for Ollama (Llama3.2, 3b and 1b) — aidatatools, October 2024 (~3.3–5.8 tokens/second)
- Mistral Compute — Mistral AI, 2025
- Mistral secures $830 million in debt financing to fund AI data center — CNBC, March 2026
- Mistral AI announces billion-dollar AI infrastructure push in Sweden — CNBC, February 2026
- Mixtral-8x7B-Instruct-v0.1 Model Card — Hugging Face (Mistral AI), 2023
- Mistral-7B-v0.1 Model Card — Hugging Face (Mistral AI), 2023
- DeepSeek Privacy Policy — DeepSeek, 2025
- DeepSeek-R1 Model Card — Hugging Face (DeepSeek), 2025
- DeepSeek-V3 Model Card — Hugging Face (DeepSeek), 2024
- Intelligenza artificiale: il Garante privacy blocca DeepSeek — Garante per la protezione dei dati personali, 30 January 2025
- AP News: Feroot Finds DeepSeek's Link to China Mobile — Feroot Security, 2025
- Researchers link DeepSeek's chatbot to Chinese Mobile, telecom banned from operating in U.S. — PBS NewsHour (Associated Press), 2025
- How Perplexity Enterprise Pro Keeps Your Data Secure — Perplexity AI, 2025
- Perplexity Enterprise Security — Perplexity AI, 2025
- Audit Logs — Perplexity Help Center — Perplexity AI, 2025
- AI Security and Data Protection — Cohere, 2026
- Enterprise Data Commitments — Cohere, 2026
- c4ai-command-a-03-2025 Model Card — Hugging Face (Cohere Labs), 2025
- Inside the Einstein Trust Layer — Salesforce Developer Blog, 2023
- Optimizing AI Response with Salesforce Einstein — Salesforce Trailhead, 2026
- Hyperforce EU Operating Zone – General Information and FAQ — Salesforce Help, 2026
- Salesforce Compliance – Certifications — compliance.salesforce.com, 2026