Loading the catalogue…
Loading the catalogue…
IBM Granite is produced by International Business Machines, a large US-headquartered public technology company incorporated in New York, making it subject to CLOUD Act and FISA 702 compelled-access risk — a material consideration for EU regulated-sector deployments. On the positive side, Granite's trust posture is among the strongest in the open-weights market: models from Granite 3.0 onward are fully Apache 2.0 licensed with publicly disclosed training datasets, IBM provides uncapped IP indemnity for Granite models on watsonx.ai, and IBM has signed the EU GPAI Code of Practice. IBM holds a broad portfolio of ISO certifications (including ISO 27001, 27017, 27018, and 27701) and operates EU data centres, though the parent entity remains a US corporation with full CLOUD Act exposure.
IBM is a US-incorporated, US-headquartered corporation. It is definitively subject to the CLOUD Act, meaning US authorities can compel IBM to disclose data held anywhere in the world. For EU regulated-sector customers (finance, healthcare, government), this is a material sovereignty risk for any cloud-hosted inference. On-premises deployment of open-weights Granite models mitigates this for the inference leg but not for any cloud-connected services.
IBM is subject to FISA Section 702, enabling US intelligence agencies to compel access to communications and data held by IBM or flowing through IBM-operated infrastructure. This applies regardless of where the data physically resides.
As a GPAI model provider, IBM must comply with EU AI Act GPAI obligations (in force from August 2025 for new models; August 2027 for models already on market). IBM has signed the GPAI Code of Practice which grants presumption of conformity. Residual risk: Granite's training data disclosure template obligations under Article 53(1)(d) are mandatory and legally binding — any gaps in public training data summaries could trigger enforcement.
IBM as a US company processing EU personal data relies on EU-US Data Privacy Framework and SCCs for cross-border transfers. The DPF adequacy decision was upheld in September 2025, but its long-term stability remains subject to political and legal risk. Customers should maintain SCC backup arrangements.
Stav AI Act assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
IBM publicly discloses Granite training datasets for all major releases. The Granite 3.0 and 4.1 technical reports detail data sources, filtering methodology, and benchmark results. IBM explicitly rejects the industry trend of 'cryptic concealment of training data.'
IBM has signed the EU GPAI Code of Practice (July 2025), a voluntary compliance tool endorsed by the European Commission that provides presumption of conformity with EU AI Act GPAI obligations.
IBM provides uncapped IP indemnity for all IBM-developed Granite models on watsonx.ai, and does not require customers to indemnify IBM in return — a uniquely strong stance in the market.
IBM holds an extensive portfolio of ISO certifications applicable to its AI and cloud services: ISO 27001, 27017, 27018 (PII in public clouds), 27701 (privacy), 22301, and ISO 42001 (responsible AI). These provide strong third-party assurance for enterprise customers.
Granite 4.1 and 4.0 models are released with cryptographic signatures and ISO certifications alongside full transparency disclosures, providing a verifiable chain of provenance from training to deployment.
Granite models are available via Apache 2.0 open weights on HuggingFace, Ollama, NVIDIA NIM, and Google Vertex AI. IBM maintains 24 public GitHub repositories and community workshops. Open-weights deployment allows EU customers to run models on-premises without cloud dependency.
IBM is a large, financially stable public corporation with a 100+ year history and a rapid Granite model release cadence (v3.0 through v4.1 in under 18 months). The Granite family is the AI backbone of multiple IBM products, ensuring long-term maintenance commitment.
Privacy policy review
Creator profile
IBM Granite is a United States entity. Training data and weights produced under United States-jurisdiction are covered by the CLOUD Act.
Exposed on training. Inference is unaffected when hosted on Stav infrastructure inside the EEA.
Stav compliance has not yet scored IBM Granite. Scores are published once the policy review and infrastructure assessment complete.
Findings
Citations gathered when the Compliance Curator last reviewed this creator’s public-facing documents. Grouped by source so the picture stays auditable.
“In contrast to the industry trend of increasingly cryptic concealment of training data, IBM continues to disclose the Granite pretraining datasets. In...”
“And contrary to some other providers of Large Language Models and consistent with IBM’s standard approach on indemnification, IBM does not require its...”
“IBM has obtained Corporate certifications for ISO 9001 (quality management system), ISO 14001 & ISO 50001 (environmental system) and ISO 45001 (oc...”
UNITED STATES SECURITIES AND EXCHANGE COMMISSION WASHINGTON, D.C. 20549 FORM 8-K CURRENT REPORT PURSUANT TO SECTION 13 OR 15 (d) OF THE SECURITIES E...
IBM Granite is a series of decoder-only AI foundation models created by IBM. It was announced on September 7, 2023, and an initial paper was published...
IBM’s push into large language models began in earnest in late 2023 with the debut of the Granite foundation model family, starting with models like G...
All Granite 4.1 models are released under an Apache 2.0 license, reinforcing IBM Research’s commitment to open, transparent innovation.
The Commission maintains a list of signatories. Current signatories include Amazon, Google, IBM, Mistral AI and OpenAI.
The Commission and the AI Board have confirmed that the code is an adequate voluntary tool for providers of GPAI models to demonstrate compliance with...
UNITED STATES SECURITIES AND EXCHANGE COMMISSION WASHINGTON, D.C. 20549 FORM 8-K CURRENT REPORT PURSUANT TO SECTION 13 OR 15 (d) OF THE SECURITIES E...
IBM Granite is a series of decoder-only AI foundation models created by IBM. It was announced on September 7, 2023, and an initial paper was published...
IBM’s push into large language models began in earnest in late 2023 with the debut of the Granite foundation model family, starting with models like G...
All Granite 4.1 models are released under an Apache 2.0 license, reinforcing IBM Research’s commitment to open, transparent innovation.
The Commission maintains a list of signatories. Current signatories include Amazon, Google, IBM, Mistral AI and OpenAI.
The Commission and the AI Board have confirmed that the code is an adequate voluntary tool for providers of GPAI models to demonstrate compliance with...
IBM's Granite Guardian models — purpose-built safety and content moderation models released under Apache 2.0 — rank in the top 10 on the GuardBench Leaderboard, providing enterprise customers with auditable safety layers for regulated deployments.
Published safeguards & certifications
“Whatever you do in watsonx, you retain ownership of your data. We don’t use your data to train our models; you retain control of the models you build ...”
“The Commission and the AI Board have confirmed that the code is an adequate voluntary tool for providers of GPAI models to demonstrate compliance with...”
“IBM Granite is a series of decoder-only AI foundation models created by IBM. It was announced on September 7, 2023, and an initial paper was published...”
“The Commission maintains a list of signatories. Current signatories include Amazon, Google, IBM, Mistral AI and OpenAI. ”
“All Granite 4.1 models are released under an Apache 2.0 license, reinforcing IBM Research’s commitment to open, transparent innovation. ”
“UNITED STATES SECURITIES AND EXCHANGE COMMISSION WASHINGTON, D.C. 20549 FORM 8-K CURRENT REPORT PURSUANT TO SECTION 13 OR 15 (d) OF THE SECURITIES E...”
“IBM’s push into large language models began in earnest in late 2023 with the debut of the Granite foundation model family, starting with models like G...”
As classified under Regulation (EU) 2024/1689.
Provider of GPAI model (general-purpose).
In contrast to the industry trend of increasingly cryptic concealment of training data, IBM continues to disclose the Granite pretraining datasets. In...
And contrary to some other providers of Large Language Models and consistent with IBM’s standard approach on indemnification, IBM does not require its...
IBM has obtained Corporate certifications for ISO 9001 (quality management system), ISO 14001 & ISO 50001 (environmental system) and ISO 45001 (oc...
Whatever you do in watsonx, you retain ownership of your data. We don’t use your data to train our models; you retain control of the models you build ...
In contrast to the industry trend of increasingly cryptic concealment of training data, IBM continues to disclose the Granite pretraining datasets. In...
And contrary to some other providers of Large Language Models and consistent with IBM’s standard approach on indemnification, IBM does not require its...
IBM has obtained Corporate certifications for ISO 9001 (quality management system), ISO 14001 & ISO 50001 (environmental system) and ISO 45001 (oc...
Whatever you do in watsonx, you retain ownership of your data. We don’t use your data to train our models; you retain control of the models you build ...