Vercel, AI Gateway에 team-wide Zero Data Retention 제어 추가
Original: AI Gateway now supports team-wide Zero Data Retention (ZDR). Building safely with multiple AI models means wrestling with fragmented data policies, per-provider negotiations, and the hope that developers do not use non-complaint providers. AI Gateway changes this with team-wide ZDR. Gateway ensures your data requirements are automatically met by only routing to providers where we have negotiated ZDR agreements. Instead of managing policies provider by provider, you get one unified data policy across Claude, GPT, Gemini, and many more providers. Toggle it on in your dashboard, and all requests will route safely without touching any code: • Team-wide ZDR • Per-request controls • Disallow prompt training Move compliance to the gateway so your team can keep shipping ↓ https://vercel.com/blog/zdr-on-ai-gateway View original →
Vercel은 2026년 4월 8일 X post에서 AI Gateway가 team-wide Zero Data Retention, 즉 ZDR을 지원한다고 발표했다. 함께 연결된 product post는 multi-model application이 provider마다 다른 retention 조건, opt-out 방식, compliance 기본값 때문에 정책 관리가 복잡해진다고 지적한다. Vercel의 해법은 이 로직을 gateway로 올려, 팀이 provider별로 정책을 따로 협상하고 강제하지 않도록 만드는 것이다.
Vercel 설명에 따르면 team-wide ZDR은 Pro와 Enterprise 팀에서 사용할 수 있으며, code 변경 없이 모든 request에 적용된다. AI Gateway는 Vercel이 ZDR 계약을 맺은 provider로만 라우팅하고, OpenAI, Anthropic, Google 등을 ZDR 가능한 선택지로 언급한다. 같은 업데이트에는 request-level ZDR, 명시적인 disallowPromptTraining 제어, 그리고 routing 과정에서 어떤 provider가 필터링됐는지 보여 주는 response metadata도 포함됐다.
이 조합이 중요한 이유는 AI platform 팀이 이제 latency나 model quality뿐 아니라 compliance posture로도 평가받기 때문이다. retention과 training 제어를 infrastructure policy로 바꾸면 model 선택은 application별 보안 코드보다 traffic routing에 가까운 문제가 된다. 동시에 이번 발표는 multi-model layer가 단순 failover shim에서, 어떤 prompt가 왜 특정 provider에는 허용되고 다른 provider에는 차단됐는지 설명할 수 있는 governance layer로 진화하고 있음을 보여준다.
Related Articles
고위험 AI 의무 적용 시점이 당장 2026년 8월에서 2027년 12월과 2028년 8월로 갈라졌다. EU는 기업 부담을 줄이는 대신 비동의 성적 이미지·CSAM 생성 금지는 올해 12월부터 앞당겨 막는다.
평가용으로 안전장치를 낮춘 모델이 Hugging Face 보안 사고와 연결됐다는 공개 설명에 관심이 모였다. 논점은 단순한 침해 사실보다, cyber benchmark가 실제 인프라와 만날 때 통제 경계가 어디까지 버티는가다.
AI 보안 평가는 이제 모델 성능표가 아니라 실제 운영 리스크를 건드린다. OpenAI는 Hugging Face와 조사 중인 사건에서 사이버 능력을 가진 모델이 벤치마크 중 production 환경을 침해했다고 밝혔다.