Build vs Buy — Enterprise AI Platform Comparison
A structured comparison of the five managed AI inference platforms used by Australian enterprises — scored on data residency, APRA CPS 234 readiness, Sydney latency, and use-case fit. Written for CTOs and CIOs making a procurement decision in 2026.
Platforms Evaluated
Azure OpenAI
Microsoft
AWS Bedrock
Amazon
Google Vertex AI
Cloudflare AI
Cloudflare
Direct API
OpenAI / Anthropic / Google
Platform Comparison
Ten dimensions ranked by procurement priority for APRA-regulated and Privacy Act–covered Australian enterprises.
Scroll right to see all platforms →
| Dimension | Azure OpenAIMicrosoft | AWS BedrockAmazon | Google Vertex AIGoogle | Cloudflare AICloudflare | Direct APIOpenAI / Anthropic / Google |
|---|---|---|---|---|---|
AU Data Residency Does customer data stay within Australian borders at rest and in transit? | ✓ Australia East | ✓ ap-southeast-2 | ✓ australia-southeast1 | Edge (global) | ✗ US-based |
AU Region / PoPs Physical compute presence serving Australian traffic. | Australia East & Southeast | Sydney (ap-southeast-2) | Melbourne & Sydney | 300+ global PoPs | No AU DC |
APRA CPS 234 Ready Ability to provide audit evidence, penetration test results, and third-party assessment reports required under APRA CPS 234. IRAP (Information Security Registered Assessors Program) assessment — carried out by an ASD-endorsed independent assessor against the Australian Government Information Security Manual — is the key credential, but it is not a single blanket certification: assessments are specific to individual services, deployment types, and regions, and must be checked per-service. Microsoft and AWS both publish IRAP assessments covering select services up to the PROTECTED level in Australian regions; Google Cloud publishes IRAP assessment material for select services. Cloudflare and Direct API providers do not publish IRAP assessments. Always confirm the current assessment scope for the specific service you intend to use. | Strong | Strong | Moderate | Moderate | Weak |
Privacy Act Compliance Contractual support for the Australian Privacy Act 1988 (APPs). MCCA = Microsoft Cloud Agreement AU; DPA = Data Processing Agreement. | Yes (MCCA) | Yes (AWS DPA) | Yes (GCP DPA) | Yes | Limited |
Models Available | GPT-4o, o3, o1 | Claude 3.7, Llama 3.3, Titan | Gemini 2.0, PaLM | Llama 3.3, Mistral | GPT-4o, Claude, Gemini |
Latency from Sydney Approximate p50 round-trip from Sydney. Cloudflare serves from the nearest PoP; direct APIs route to US datacentres. | ~180 ms | ~120 ms | ~160 ms | ~30 ms | ~300 ms+ |
Pricing Indicator Relative cost tier for inference at scale. $ = lowest, $$$ = premium. Representative published on-demand rates per 1M tokens, USD, standard tier: Azure OpenAI GPT-4o — $5.00 input / $15.00 output. AWS Bedrock Claude 3.5 Sonnet — $6.00 input / $30.00 output (Public Extended Access pricing; varies by region). Google Vertex Gemini 2.5 Pro — $1.25 input / $10.00 output (≤200K context). Cloudflare Workers AI Llama 3.3 70B — $0.29 input / $2.25 output. Direct API pricing follows the underlying provider's published consumer/API rate card. Pricing as of July 2026, USD, per-model — check each vendor's pricing page for current rates; figures exclude currency conversion, GST, and regional/tier variation. | $$$ | $$ | $$ | $ | $$ |
Enterprise SLA Published uptime commitment. Verify the specific tier for your contract — base SLAs may differ from premium tiers. | 99.9% | 99.95% | 99.9% | 99.99% | 99.5% |
Fine-tuning Support | Yes | Yes | Yes | No | Yes (limited) |
Agentic / Tool Use Native support for function calling, tool use, multi-step agents, and orchestration frameworks. | Strong | Strong | Strong | Moderate | Strong |
Latency values are approximate p50 from Sydney; actual results vary by model, payload size, and time of day. Pricing indicators are relative — request quotes for workload-specific costs. APRA and Privacy Act assessments are AEAI analysis based on public documentation — obtain independent legal advice before procurement decisions.
Use Case Fit Matrix
Platform suitability by workload type. High = strong native support; Medium = possible with additional tooling; Low = significant gaps or unsupported.
Scroll right to see all platforms →
| Use Case | Azure OpenAI | AWS Bedrock | Google Vertex AI | Cloudflare AI | Direct API |
|---|---|---|---|---|---|
RAG at scale Cloudflare Workers AI lacks managed vector search at scale; use in combination with Vectorize for lighter workloads. | High | High | High | Low | Medium |
Agentic workflows | High | High | High | Low | High |
Batch processing Bedrock and Vertex have native async batch APIs. Azure Batch is available but fewer models support it. | Medium | High | High | Low | Medium |
Realtime / low latency Cloudflare Workers AI runs at the edge closest to the user — the only option delivering sub-50ms Sydney latency. | Low | Low | Low | High | Low |
APRA-regulated workloads APRA CPS 234 requires documented third-party risk management and penetration test evidence. Azure and AWS Bedrock have published IRAP assessments for select services in Australian regions — confirm the specific service and region is in scope before relying on it. | High | High | Medium | Low | Low |
On-prem / sovereign No cloud platform meets true air-gap sovereignty requirements. Consider quantised SLMs (Phi-4, Llama 3.3 8B) on Dedicated Hardware. | Low | Low | Low | Low | Low |
On-premises / sovereign deployments
APRA CPS 234 — Third-Party & Offshore Risk
Direct API (OpenAI / Anthropic endpoints in the US) requires additional third-party risk documentation for APRA-regulated entities.
For APRA-regulated entities (ADIs, insurers, superannuation funds) processing customer financial data: routing inference to an AI provider is a material third-party arrangement under CPS 234, which requires the entity to maintain information security controls commensurate with the sensitivity of the data, assess the security capability of any party that holds or processes it, and notify APRA of information security incidents and control weaknesses it cannot remediate in a timely manner. An independently published IRAP assessment covering the specific service and Australian region in use can support this due-diligence, but does not by itself satisfy the entity's CPS 234 obligations. Cloudflare's edge-routing model and Direct API require the same third-party risk assessment as any other provider before use with regulated customer data. This is general information, not legal or compliance advice — confirm current obligations against the full text of CPS 234.
Key Recommendations
AEAI analysis distilled into three decision-ready recommendations for Australian enterprise.
Best for APRA Compliance
Both publish IRAP assessments for select services in Australian regions and offer AU data residency with contractual Privacy Act coverage — confirm the specific service is in scope for your workload. Azure has the deepest Australian banking reference architecture; Bedrock offers more model choice.
See APRA guidance on third-party risk →Best for Latency
Workers AI delivers ~30ms p50 from Sydney by running inference at the nearest PoP. The trade-off is model range (Llama 3.3 + Mistral only) and no AU data residency commitment — data is processed at the nearest PoP globally. Use for latency-sensitive features that do not involve regulated or sensitive data.
Best for Model Choice
Calling OpenAI, Anthropic, and Google APIs directly gives you access to every frontier model the day it ships — no managed-service lag. The cost is data residency (US datacentres), higher latency from Sydney (~300ms+), and limited contractual compliance support. Suitable for internal tooling, rapid prototyping, and non-regulated workloads.
Australian-Specific Considerations
APRA CPS 234
APRA-regulated entities (banks, insurers, superannuation funds) must treat AI providers as material third parties under CPS 234. Require a current IRAP assessment, defined SLAs, right-to-audit clauses, and incident notification terms. Azure and Bedrock maintain IRAP assessments with AU data residency; others do not.
Privacy Act 1988 (APPs)
The Australian Privacy Principles (APPs) require that personal information is protected with contractual safeguards when disclosed to overseas providers. All hyperscalers offer DPAs covering AU law; Direct API providers offer limited contractual coverage and data is processed outside Australia.
Latency from Australian Cities
Sydney to US West Coast is ~160ms one-way; users in Melbourne or Perth add further distance. For interactive AI features (copilots, assistants), AU-resident deployments (Bedrock ap-southeast-2, Vertex australia-southeast1) deliver material UX improvement over Direct API. Cloudflare is the only sub-50ms option.
AU Pricing Uplift
Hyperscaler AU regions typically attract a 10–20% pricing premium over US regions for compute and inference. This is partially offset by lower egress costs for AU-resident data. Factor regional pricing differentials into TCO models, especially for high-volume batch workloads.
Vendor Lock-in Risk
Managed platforms abstract the model layer — a model deprecation (e.g. GPT-3.5 EOL, Titan Text deprecation) forces migration. Design abstractions via a common inference interface (LangChain, LlamaIndex, or a thin internal gateway) that decouples application code from provider APIs. Direct API access gives the most portability but at higher operational cost.
Sovereignty vs Capability Trade-off
The most capable frontier models (GPT-4o, Claude 3.7 Sonnet, Gemini 2.0 Ultra) are only available via managed cloud platforms — no fully sovereign option exists at this capability tier. Where PROTECTED-level sovereignty is required, a tiered approach (SLM on-prem + managed cloud for non-sensitive workloads) is the pragmatic architecture.
From platform selection to maturity measurement
How does your AI programme compare to peers?
Choosing the right platform is one part of enterprise AI maturity. Use the AEAI Benchmark to score your organisation across Adoption, Governance, Investment, and Incidents — and see where you rank against the Q2 2026 national index.
Platform scores and assessments are based on publicly available documentation, IRAP disclosures, and AEAI signal analysis as at June 2026. Vendor capabilities change frequently — verify current terms with each provider. This page does not constitute legal, regulatory, or procurement advice. Contact AEAI to flag an update or inaccuracy.