Anthropic (Claude) — US-based, but offers zero-retention API
OpenAI (GPT) — US-based, zero-retention on API
DeepSeek — China-based, consider implications
Self-hosted models (Llama, Mistral) — data never leaves your server
Zero-Retention API Usage
Both Anthropic and OpenAI offer API tiers where they don't retain your input/output data. This is important for GDPR — the model provider processes but doesn't store your data.
EU AI Act Considerations
The EU AI Act introduces additional requirements from August 2026:
Risk Classification
Personal AI assistants like OpenClaw are generally classified as limited risk — requiring transparency obligations but not the full requirements of high-risk systems.
Transparency Requirements
Users must be informed they're interacting with AI
AI-generated content should be identifiable
Keep logs of AI system operation
What This Means in Practice
For personal use, the requirements are minimal. For business use with customer-facing AI, ensure:
Clients know they're interacting with AI
You can explain what data the AI accesses
You maintain audit logs
Practical Compliance Checklist
Data Processing Agreement
If using managed hosting, ensure your provider offers a DPA (Data Processing Agreement).
Privacy Policy
Update your privacy policy to mention:
Use of AI assistant technology
What data the AI accesses
How data is processed and stored
Third-party model provider information
Data Subject Rights
Ensure you can fulfill:
Right of access — show people what data the AI has about them
Right to erasure — delete specific memories and data
Right to portability — export data in a standard format
OpenClaw's file-based memory system makes this straightforward — memory files are human-readable Markdown.