Registry / Llama via AWS Bedrock
Llama via AWS Bedrock
Meta's Llama models served through Amazon Bedrock, AWS's managed foundation-model service. Vendor-trust and data-handling posture is AWS's (SOC/ISO scope, AWS BAA, GDPR DPA, Bedrock retention controls); EU AI Act provider obligations (GPAI Code of Practice, Art 53) sit with Meta as the model developer. Meta is absent from the EC's GPAI Code of Practice signatory list, and current-generation Llama models on Bedrock are served in US geography only.
Watch-outs 5
The cells where this offering is not a clean public yes. This is what to check before you sign.
- SOC 2 Type II: Partial SOC 2 covers the AWS Bedrock platform; Llama (Meta) itself is not individually in the scope of the report.
- ISO 27001: Partial AWS's ISO 27001 covers the Bedrock service/platform, not Meta's Llama model itself; no public evidence of Meta's own ISO 27001 covering Llama.
- ISO 42001: Partial Only AWS Bedrock service is ISO/IEC 42001 certified; no public evidence of Meta's own certification.
- HIPAA BAA: Yes, sales-gated BAA is obtained via gated, account‑based process (AWS Artifact/self‑service portal)
- GPAI Code: No, verified list updated 31 July 2026; Meta not present
AWS's own services-in-scope page lists Amazon Bedrock as in scope for SOC 1/2/3, but the third-party Llama model is not individually certified, so per the platform-vs-model rule this is partial.
"[Amazon Bedrock](/bedrock/) [excludes Amazon Bedrock Marketplace] | ✓" indicates Amazon Bedrock is in scope for AWS SOC 1,2,3 reports.
AWS's ISO/IEC 27001 scope lists only the Bedrock platform service ("Amazon Bedrock [excludes amazon Bedrock Marketplace]" on aws.amazon.com/compliance/iso-certified/), and per the platform-vs-model rule a platform certificate does not certify the third-party Llama model, so the value is partial rath
Amazon Bedrock [excludes amazon Bedrock Marketplace]
AWS’s ISO/IEC 42001 accreditation applies to Bedrock, and there is no publicly available ISO/IEC 42001 certification for Meta, the Llama developer, making the model’s certification partial.
covering: Amazon Bedrock
AWS publicly documents the AWS Artifact portal, confirming a maintained compliance portal for the offering.
Save time with on‑demand access to AWS and Independent Software Vendor (ISV) compliance reports in a self‑service portal.
Amazon Bedrock is listed as a HIPAA‑eligible service, and AWS requires a Business Associate Agreement to use any such service, which is only available through a gated, account‑based process.
NOTE: If you are a Covered Entity or Business Associate ... you agree not to use these HIPAA Eligible Services ... without first entering into an AWS business associate agreement.
The AWS GDPR DPA is publicly hosted on AWS's own domain, incorporates the Standard Contractual Clauses (Section 1.2), and Section 6.1 confirms the public sub-processor list at aws.amazon.com/compliance/sub-processors/, which is live and lists engaged sub-processors without a gate.
Customer can use the Service Controls to assist it with its obligations under Applicable Data Protection Law... Customer Data transferred under the Standard Contractual Clauses is inaccurate or outdated... The AWS website (currently posted at https://aws.amazon.com/compliance/sub-processors/) lists Sub-processors that are currently engaged by AWS.
The AWS Bedrock FAQ publicly states that customer content is not used to improve base models, confirming a default commitment not to train on API data.
With Amazon Bedrock, your content is not used to improve the base models and is not shared with any model providers.
AWS docs publicly describe a zero‑data‑retention mode and point to a list of models that require retention; Llama is absent from that list, confirming zero‑retention is supported for Llama via Bedrock.
"Zero data retention. No request or response data is written to durable storage by AWS or shared with the model provider. ... For a full list of models requiring data retention, see Amazon Bedrock abuse detection."
The model card’s Regional Availability table lists EU regions in the In-Region column, confirming data can be pinned to a specific EU AWS region.
Region | In-Region | Geo | Global `eu-central-1` (Frankfurt) | ![]() | ![]() | ![]() `eu-west-1` (Ireland) | ![]() | ![]() | ![]() `eu-west-3` (Paris) | ![]() | ![]() | ![]()
Meta, the developer of Llama, is absent from the EU Commission's complete GPAI Code of Practice signatory list, which is authoritative and complete, confirming a verified no.
"## Signatories of the code of practice ...\n- AI Studio Delta\n- Aleph Alpha\n- Almawave\n- Amazon\n- Anthropic\n- Black Forest Labs\n- Bria AI\n- Cohere\n- Domyn\n- Dweve\n- Fastweb\n- IBM\n- LINAGORA\n- Microsoft\n- Mistral AI\n- Open Hippo\n- OpenAI\n- Pleias\n- ServiceNow\n- WRITER"
The row is "Llama via AWS Bedrock" — a serving-platform row — and the rubric states art53_summary is a DEVELOPER obligation making serving-platform rows not_applicable; additionally the cited transparency page covers only the separate Art 53(1)(d) transparency obligation, not the 53(1)(c) training-c
EU AI Act Transparency Reports. These reports are published by Meta Platforms Ireland Limited pursuant to Article 53(1)(d) of Regulation (EU) 2024/1689 (AI Act).
Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.