llm-integration.eu

Managed AI Services for Claude: RACI and GDPR Duties

What a Claude managed service takes over and what stays with you: a RACI across company, provider, AWS or Google and Anthropic, plus GDPR Art. 28 and SLA terms.

Updated 11 min readFacts verified on 1 October 2026

TL;DR

Managed AI services for Claude cover the operating layer: accounts, IAM, network, guardrails, cost control, logging and model upgrades. The cloud provider runs the infrastructure and Anthropic the model. Your company stays accountable for data, use cases and GDPR. Contract the provider as an Art. 28 processor, with a 99.9% baseline and a clean exit.

What does a Claude managed service actually take over?

A Claude managed service takes over the customer side of the cloud shared responsibility model. AWS or Google secure the infrastructure and the model endpoint. Everything you configure on top stays your job: identities, network paths, retention settings, logs, budgets, guardrails and model choice. A managed service provider does that configuration work for you, under contract.

AWS draws the line in its shared responsibility model: AWS is responsible for “the infrastructure that runs all of the services”, the customer for security in the cloud, including data, encryption options and IAM permissions. The Bedrock data protection page applies that model to Claude and adds a point that matters for the RACI below: model providers “don’t have any access” to the Bedrock deployment accounts, logs, prompts or completions. On Bedrock, Anthropic is not in your data flow.

Google states the same split for its AI platform, now called Gemini Enterprise Agent Platform (formerly Vertex AI). The shared responsibility page makes the customer responsible for access controls, application security, incident monitoring and legal compliance for its use cases.

So there are four parties, and the provider in the middle is the only one you choose freely:

Party Role in a Claude setup Typical contract
Your company Controller for personal data, owner of use cases and budget n/a
Managed service provider Operates your cloud account configuration and the gateway layer Service contract plus Art. 28 DPA
Cloud provider (AWS, Google) Runs infrastructure and the Claude endpoint Cloud terms plus provider DPA
Anthropic Trains and ships the model; processor only on its own API Commercial Terms plus Anthropic DPA

If you are still choosing the cloud route, our GDPR comparison of Claude providers covers residency and retention for each option.

Who is responsible for what? The RACI for a managed Claude setup

The provider is responsible (R) for most build and run tasks. Your company stays accountable (A) for every decision with legal or financial weight: which data enters prompts, which models are allowed, who gets access, and which processors you authorise. AWS, Google and Anthropic are consulted or informed, never accountable for your configuration.

The matrix below is our recommendation for a Bedrock or Google Cloud setup with an external operator. R = responsible, A = accountable, C = consulted, I = informed.

Activity Company Managed service provider Cloud provider Anthropic
Account, project and quota setup A R C (quota increases) I
IAM and SSO integration A, C R I n/a
Network and private endpoints A R C n/a
Model access and allowlist A R I C (use case form)
Guardrails and content filters A, C R I n/a
Cost control and budgets A R I n/a
Logging and observability A R I n/a
Model upgrades and migrations A, C R I (Legacy and EOL dates) I (deprecations)
Incident response A R R (infrastructure) C (model behaviour)
DPA and subprocessor management A, R R (own subprocessors) C C (API route only)
User training and AI literacy A, R C n/a n/a

Five rows carry most of the risk, and each has a concrete setting behind it:

  • Model access. Bedrock enables foundation models by default when the right Marketplace permissions exist. For Anthropic models, the model access page requires a one-time First Time Use form per account or per organisation management account. AWS also notes that denying aws-marketplace:Subscribe alone does not block the first invocation. Blocking needs a Deny on bedrock:InvokeModel via SCP or IAM. That policy is a company decision, implemented by the provider.
  • Retention. Bedrock data retention is set per Region and does not propagate. Claude Fable 5 and 5.1 require aws_review, which retains prompts and completions inside AWS for up to 30 days. Allowing that mode is your call, not the operator’s.
  • Logging. Model invocation logging is disabled by default. Once enabled, full request and response bodies up to 100 KB land in CloudWatch Logs or S3, and logs are kept until the configuration is deleted. Those logs are personal data if prompts are. Retention periods and read access belong in your DPA.
  • Quotas. Bedrock quotas apply per account and are tracked separately for bedrock-runtime and bedrock-mantle. The operator files increase requests, but you decide which workloads get capacity.
  • Model upgrades. On Bedrock, only the model card dates apply. The lifecycle page lists Legacy periods of 6 months or 45 days, and existing customers may lose access after 15 days of inactivity during Legacy. The provider must track this calendar for you.

For the Bedrock-specific mechanics behind these rows, see our Amazon Bedrock EU guide.

How does the GDPR Art. 28 processor chain work?

Your company is the controller. The managed service provider is your processor if it can access prompts, logs or configuration containing personal data. AWS or Google are processors too, contracted either directly by you or as the provider’s sub-processors. Anthropic enters the chain only when you call the Anthropic API directly.

Article 28 GDPR sets three rules that shape every managed service contract:

  1. Art. 28(2): a processor “shall not engage another processor without prior specific or general written authorisation of the controller”. Under a general authorisation, you must be told of intended changes and get the chance to object.
  2. Art. 28(3)(g): at the end of the service, the processor deletes or returns all personal data, at your choice.
  3. Art. 28(4): sub-processors carry the same obligations, and the initial processor “shall remain fully liable” for them.

Article 33(2) adds that a processor must notify the controller “without undue delay” after becoming aware of a breach. Your contract should put a number on that.

Two contract structures are common. In the first, your company holds the AWS or Google account and signs the cloud DPA directly. The AWS DPA is part of the AWS Service Terms, per the AWS GDPR Center. The provider operates inside your account and is a separate processor. In the second, the provider holds the account and bills you. Then AWS or Google becomes the provider’s sub-processor, and Art. 28(4) makes the provider liable for them. We recommend the first structure: you keep the root of trust, the cloud contract and the exit path.

If the provider routes traffic to the Anthropic API, read Anthropic’s terms first. The Commercial Terms forbid reselling the Services “except as expressly approved by Anthropic”. Ask for that approval in writing, or contract Anthropic yourself. The Anthropic DPA names the customer as controller and Anthropic as processor, gives 15 days to object to a new subprocessor, promises breach notice within 48 hours and return or deletion within 30 days after termination. Anthropic’s privacy center also states that access through a third-party platform is governed by that platform’s terms, not by the Anthropic DPA.

Which service levels should a Claude managed service contract define?

Define service levels for the layer the provider controls, and inherit the cloud SLA for the layer it does not. AWS commits to 99.9% monthly uptime for Amazon Bedrock per Region. A provider cannot promise more availability for the model endpoint than that, but it can promise response times, change windows and upgrade lead times.

The Amazon Bedrock SLA pays service credits of 10% below 99.9%, 25% below 99.0% and 100% below 95.0%, calculated on your Bedrock charges in the affected Region. Credits go to whoever holds the AWS account. That is one more argument for keeping the account in your name.

Model lifecycles set the second clock. Anthropic gives at least 60 days’ notice before retiring a publicly released model on its own platforms, according to its deprecations page. The same page says Bedrock and Google Cloud set their own schedules. A current example: claude-sonnet-4-5-20250929 retires on the Claude API on 30 November 2026.

The figures below are our recommendation, not sourced market standards:

Service level Our recommended target Why
Endpoint availability Pass-through of the 99.9% Bedrock SLA, credits forwarded Provider does not run the model
Gateway or proxy availability (if operated) 99.9% monthly Matches the layer below
Critical incident response 1 hour, 24/7 for production use Outage blocks all users
Breach notice to you 24 hours Leaves time for your 72-hour authority notice under Art. 33(1)
Model EOL migration Tested replacement 30 days before EOL Bedrock Legacy can be 45 days
Monthly report Spend per team, quota usage, open incidents, upcoming EOL dates Basis for your accountability
Subprocessor change notice 30 days, objection right Art. 28(2)

Run it yourself or outsource?

Run Claude yourself when you already operate an AWS or Google landing zone with a platform team and the Claude use cases are internal. Outsource when nobody in house owns IAM, logging and model lifecycle as a job, or when you need 24/7 response. Never outsource the accountable decisions: data classes, model allowlist, processor approval.

What in-house operation costs in roles and recurring tasks, based on the RACI above (our estimate of the work, not a sourced benchmark):

Recurring task Frequency Role
Review IAM roles, SSO groups and API keys Monthly Cloud engineer
Check retention mode per Region and logging config Monthly and after every new Region Cloud engineer plus DPO
Watch model cards for Legacy and EOL dates Weekly Platform owner
Test and roll out replacement models Per deprecation, several times a year Developer plus business owner
Review spend per team, adjust budgets and quotas Monthly FinOps or controlling
Tune guardrails, review blocked prompts Monthly Product owner plus security
Update records of processing and subprocessor list Per change DPO

Our view: one cloud engineer at partial capacity can cover this for a few internal use cases. The equation changes with customer-facing use, with more than one cloud, or with on-call duty. That is where managed AI services earn their fee.

Outsourcing makes less sense when the provider would need broad admin rights to deliver little, when your only workload is a single Claude Code rollout, or when the provider insists on owning the cloud account. Our Claude Enterprise vs Bedrock comparison shows a route with less infrastructure to operate at all.

What to demand from a Claude managed service provider:

  1. Access model. A role in your account, assumed with temporary credentials, never IAM users with long-term keys. AWS documents this pattern for third-party access, including an external ID against the confused deputy problem.
  2. Art. 28 DPA. Instructions, confidentiality, security measures, deletion at the end, audit rights and a breach notice deadline in hours.
  3. Subprocessor list. Named, with locations, and a written notice and objection process.
  4. SLA. The table above, with service credits that are not capped at a token amount.
  5. Exit. Configuration as code in your repository, runbooks handed over, logs left in your buckets, 30 days of transition support.

A trust policy for the provider role looks like this. Replace the account ID and external ID with the values the provider gives you:

{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Principal": { "AWS": "arn:aws:iam::111122223333:root" },
    "Action": "sts:AssumeRole",
    "Condition": { "StringEquals": { "sts:ExternalId": "provider-assigned-id-for-you" } }
  }]
}

To check what the provider configured, two read-only commands, each one line:

aws bedrock get-model-invocation-logging-configuration --region eu-central-1
curl -s https://bedrock.eu-central-1.amazonaws.com/data-retention -H "Authorization: Bearer $AWS_BEARER_TOKEN_BEDROCK"

The first shows whether prompts are logged and where. The second returns the retention mode for that Region. Run both in every Region you use.

FAQ

What are managed AI services for Claude?

A managed AI service for Claude is an external operator that configures and runs your Claude environment on AWS, Google Cloud or the Anthropic API: accounts, IAM, network, guardrails, logging, budgets and model upgrades. The cloud provider still runs the infrastructure and Anthropic the model. Your company remains the GDPR controller.

What does a Claude managed service cost?

Token costs stay the same, because they are billed by AWS, Google or Anthropic. The service fee covers the operating work in the RACI. We have no sourced market price to quote. Compare offers against the in-house effort in this guide, and insist that tokens are billed to your own cloud account, not marked up.

Is the managed service provider a processor under GDPR?

Yes, if it can access personal data in prompts, logs or configuration. Article 28 then requires a written contract with instructions, confidentiality, security, deletion at the end and audit rights. Any sub-processor it uses needs your prior written authorisation, and it remains fully liable for them.

Managed service vs in-house operation: which is better?

In-house wins when you already run a cloud landing zone and Claude stays internal. A managed service wins when you need 24/7 response, run customer-facing workloads or lack a platform team. In both cases the company keeps accountability for data classes, model allowlist and processor approval.

Does Anthropic see our prompts on Bedrock?

No. AWS states that model providers have no access to the Bedrock deployment accounts, logs, prompts or completions. For Claude Fable 5 and 5.1, AWS retains prompts up to 30 days for human review by AWS, not by Anthropic. On the Anthropic API, Anthropic is your processor.

Who handles model retirements in a managed setup?

The provider tracks and tests, your company approves. Bedrock Legacy periods are 6 months or 45 days, and Anthropic gives at least 60 days’ notice on its own platforms. Bedrock and Google Cloud set their own dates, so the contract should name the model card as the reference.

Sources

  1. AWS: Shared Responsibility Model (1 October 2026)
  2. AWS: Amazon Bedrock data protection (1 October 2026)
  3. AWS: Amazon Bedrock data retention (1 October 2026)
  4. AWS: Bedrock model invocation logging (1 October 2026)
  5. AWS: Bedrock model access (1 October 2026)
  6. AWS: Bedrock model lifecycle (1 October 2026)
  7. AWS: Amazon Bedrock Service Level Agreement (1 October 2026)
  8. AWS IAM: Access to AWS accounts owned by third parties (1 October 2026)
  9. AWS GDPR Center (1 October 2026)
  10. Google Cloud: Gemini Enterprise Agent Platform shared responsibility (1 October 2026)
  11. Google Cloud: Agent Platform and zero data retention (1 October 2026)
  12. Anthropic: Commercial Terms of Service (1 October 2026)
  13. Anthropic: Data Processing Addendum (1 October 2026)
  14. Anthropic Privacy Center: DPA for commercial customers (1 October 2026)
  15. Anthropic: Model deprecations (1 October 2026)
  16. EUR-Lex: Regulation (EU) 2016/679 (GDPR) (1 October 2026)

Related guides