NEWS
Verax AI Risk Assessment is live. See what's exposed
OpenRouter Chat
OpenRouter Chat
 
Risk Overview
Moderate Risk
4.1
/10
Conversational AI
·
Text Generation
·
Knowledge Assistant
·
Research
·
Top Risks

Prompt data flows to multiple AI providers with independent and varying data policies — users must independently verify each routed provider's training and retention practices. Opt-in logging grants an extremely broad irrevocable commercial license including sublicensing and potential data sales in anonymized form. Complex multi-provider sovereignty risk.

Mitigations

Do not enable 'OpenRouter Use of Inputs/Outputs' opt-in for sensitive use cases. Enable ZDR (Zero Data Retention) routing mode. Review the specific provider being used for each model — check openrouter.ai/docs for provider-specific data retention policies. Consider the trust center for compliance documentation. For sensitive workloads, use API directly with providers that have contractual DPAs.

Get started
Is your team using 
OpenRouter Chat
 
safely?

Highest Risk Categories

The highest-scoring risk categories identified in this assessment.

Legal Terms

Governed by New York law, exclusive jurisdiction in New York state and federal courts. Full ToS content not rendered during research. If logging opted in, grants perpetual, irrevocable, sublicensable, royalty-free license to use, reproduce, modify, and distribute user content, including licensing or selling in anonymized form. This is a very broad commercial license for opted-in data. Dispute resolution specifics not confirmed.
6
/10

3rd-Party Sharing

Routes prompts to multiple underlying AI providers (OpenAI, Anthropic, Google, Meta, Mistral, etc.) — each with their own data policies. OpenRouter explicitly states it does not control or take responsibility for LLM providers' handling of inputs including model training. Users must review each provider's terms separately. This multi-provider pass-through is the core data risk.
5
/10

Data Sovereignty

OpenRouter itself is a US company (New York law). However, prompts are routed to various AI providers globally. The sovereignty risk depends on which provider is selected. Some providers may process data in jurisdictions outside the US/EU. ZDR mode helps but jurisdiction of underlying providers varies. US CLOUD Act applies to OpenRouter itself.
4
/10

Unlock the complete assessment

Run a free assessment to access the full AI tool risk analysis.
Start Free Assessment
Updated July 2026 • AI-assisted research • Reviewed by Verax • Report an issue

Reference Documentation

Official documentation and policies referenced as part of this assessment.