Australia's GPU cloud market just crossed a line that "data residency" alone doesn't cover anymore. On January 31, 2026, the Australia-US CLOUD Act Agreement entered into force, giving US law enforcement a direct, treaty-backed channel to compel data from any US-incorporated provider's Australian region, Sydney data centre or not. Nine days earlier, SCX.ai switched on the country's first sovereign AI inferencing node at Equinix Sydney. In June, Sharon AI signed NVIDIA for 40,000 GB300 GPUs on Australian soil. Anyone comparing GPU cloud providers in Australia now has to answer two separate questions before picking one: where does the data sit, and whose law reaches it there.
This guide breaks down what actually changed, what Australia's Privacy Act requires when you send data overseas, which providers have real Sydney and Melbourne GPU capacity today, and how that stacks up against neocloud pricing. For the wider region, see our GPU cloud guide for Asia-Pacific, which covers Singapore, Tokyo, and Seoul alongside a shorter Australia section this post expands on. For the equivalent country-level breakdown elsewhere in APAC, see our South Korea GPU cloud guide.
What the Australia-US CLOUD Act Agreement Actually Changes
The short version: it's a faster legal pipe for the same access US authorities already had, not a new surveillance power. Before the Agreement, US law enforcement seeking data held by a US-incorporated provider's overseas subsidiary went through mutual legal assistance treaty channels, a process that commonly takes months. The Agreement lets each government's law enforcement agencies request data directly from providers in the other's jurisdiction, and it works both ways, so Australian agencies get the same direct channel into US-incorporated providers.
Timeline: 2021 Signing to January 31, 2026 Entry Into Force
The Agreement was signed on December 15, 2021, under the framework of the US CLOUD Act and Australia's Telecommunications (Interception and Access) Act 1979. Before it could take effect, the US Attorney General had to certify to Congress that Australia has "robust substantive and procedural protections for privacy and civil liberties," and both countries ran it through parliamentary and congressional review. That process took just over four years; the Agreement entered into force on January 31, 2026.
What US-Incorporated Providers (AWS, Azure, GCP) Are Now Exposed To
The Agreement's reach turns on incorporation, not server location. AWS ap-southeast-2 (Sydney), Azure australiaeast, and GCP australia-southeast1 are all operated by US-incorporated entities, so a qualifying Australian or US law enforcement request can now reach data in those regions directly, on a timeline measured in weeks rather than the old MLAT process. This is the same structural exposure the GPU cloud providers in Europe guide covers for EU-region hyperscaler instances: the CLOUD Act follows the company's incorporation, and an Australian data centre address on the invoice doesn't change who the provider answers to. Non-US-incorporated providers, including Australian-owned neoclouds, sit outside this specific bilateral channel.
For most AI training workloads on non-personal or anonymized data, this exposure isn't a practical risk. It matters when you're processing regulated personal information, health records, financial data, government workloads, where a foreign law enforcement request landing on your provider would itself be a compliance event.
Privacy Act APP 8 Requirements for Overseas AI Processing
If you're moving personal information to a GPU cloud provider outside Australia, Australian Privacy Principle 8 is the rule that governs it, and it doesn't stop at the border, it follows the data. APP 8 requires an APP entity to take reasonable steps to ensure an overseas recipient won't breach the Australian Privacy Principles before disclosing personal information to them, and the entity that discloses the data stays accountable if the overseas recipient mishandles it.
Reasonable Steps and the Seven Exceptions to APP 8.1
The OAIC's APP 8 guidance sets out what "reasonable steps" looks like in practice: it's generally expected that an entity enters an enforceable contractual arrangement with the overseas recipient, and what counts as reasonable scales with the sensitivity of the information, how well-known the recipient is, and the potential harm if something goes wrong. Practically, this means a data processing agreement with your GPU cloud provider that specifies what data types are covered, requires APP-equivalent handling, and sets out a breach response process, not a blanket ban on sending data overseas.
APP 8.1 carries seven standing exceptions: a reasonable belief the recipient is subject to a substantially similar law, the prescribed-country exception described below, the individual's informed consent, disclosures required or authorized by Australian law, a set of permitted general situations (serious threats to life or health, suspected unlawful activity, locating missing persons), and two narrower carve-outs for agencies acting under international agreements or enforcement-related activity. None of these exceptions apply to anonymized training data in the first place, because APP 8 only governs personal information. A dataset stripped of identifying fields, or model weights trained on it, falls outside APP 8's scope entirely.
The 2024 Reform: Prescribed Countries and Why It Matters for AI Vendors
The Privacy and Other Legislation Amendment Act 2024 added a new exception effective December 11, 2024: an entity can disclose personal information without going through the reasonable-steps process if the recipient is subject to the laws of a country the Governor-General has prescribed by regulation, or is a participant in a prescribed binding scheme. This is the same structural mechanism the UK's adequacy regime and the EU's GDPR adequacy decisions use, and it's the lever that will eventually let Australian regulators pre-clear specific overseas jurisdictions for AI vendor relationships rather than making every entity negotiate its own contract. As of mid-2026 the prescribed list is still being built out, so most cross-border GPU cloud relationships still run on the contractual reasonable-steps path.
GPU Cloud Sydney Data Residency: SCX.ai, Sharon AI, and What's Coming
Three announcements in the first half of 2026 turned "sovereign AI in Australia" from a policy talking point into buyable and buildable capacity.
SCX.ai's Sovereign Inference Node at Equinix SY5
SCX.ai launched Australia's first sovereign AI inferencing node on January 29, 2026, at Equinix's SY5 International Business Exchange data centre in Sydney. It's built on an ASIC-accelerated architecture through a partnership with SambaNova Systems rather than a GPU cluster, and it processes data entirely within Australian borders. The node targets financial services, healthcare, and government workloads, and supports Project MAGPiE, an Australia-focused large language model, with Servers Australia, a 100% Australian-owned company, providing technical support.
SCX.ai claims the node runs at 10x the energy efficiency of traditional GPU-based inference systems and produces the lowest carbon output per AI token of any facility currently operating in Asia-Pacific, without disclosing the underlying methodology. "We're delivering enterprise-grade AI infrastructure that doesn't require massive water consumption for cooling and operates at a fraction of the energy cost of GPU-based systems," said David Keane, SCX.ai's founder and CEO. Equinix Australia's managing director, Guy Danskine, framed the launch in terms of the same distinction this post is built around: "Sovereignty has become a critical consideration for organisations."
Sharon AI x NVIDIA: 40,000 GB300 GPUs, 72MW, Six-Year Deal
SharonAI Holdings signed a six-year AI infrastructure compute collaboration with NVIDIA in June 2026 to deploy 72 megawatts of new Australian data centre capacity, scaling up to 40,000 NVIDIA GB300 GPUs. The deal runs on a revenue-sharing and credit-support model instead of a straight equipment purchase, which lowers Sharon AI's upfront capital outlay while tying NVIDIA's return to actual utilization. Sharon AI expects more than 55,000 total NVIDIA GPUs deployed in Australia by mid-2027, taking total contracted AI factory capacity to 132MW, with 102MW already under contract to end customers. GB300 is the same NVL72 rack generation covered in our GB200 NVL72 guide, for teams comparing rack-level specs and pricing across Blackwell generations.
Firmus Project Southgate and Macquarie IC3 Super West
Firmus Technologies is running the largest of the three buildouts by dollar value. Project Southgate starts with an AU$4.5 billion initial investment and scales toward a potential A$73.3 billion across five sites, Tasmania, Melbourne, and three more capital-city facilities, targeting 1.6GW of total capacity by 2028. The Melbourne site alone is bringing 18,500 NVIDIA GB300 GPUs online by April 2026, with the combined Melbourne and Tasmania sites delivering 150MW.
On the smaller but faster-to-market end, Macquarie Data Centres topped out its IC3 Super West facility in Sydney's north data centre zone in December 2025, securing 47MW of end-state power for a facility purpose-built for GPU and HPC density, and it's on track to open in September 2026. None of these three deals put rentable, on-demand GPU capacity in a buyer's hands today. They're the pipeline that determines what Sydney and Melbourne GPU supply looks like in 2027, and the gap between announced megawatts and bookable instances is worth tracking if you're planning compute two years out. The same national push driving these deals sits inside a broader GPU shortage story: sovereign buildouts of this scale are as much a response to global GPU scarcity as they are a policy choice.
Residency vs Sovereignty: A Practical Distinction for Buyers
These two terms get used interchangeably in vendor marketing, and the difference decides which providers actually solve your compliance problem. Data residency means your data physically sits inside Australia. AWS ap-southeast-2, Azure australiaeast, and GCP australia-southeast1 all already deliver that. Sovereign AI is a stricter claim: that the infrastructure, ownership, and operational control also sit outside foreign legal jurisdiction, which is the gap the CLOUD Act Agreement just widened for US-incorporated hyperscalers.
A hyperscaler Sydney region gives you residency without sovereignty: your data stays in-country, but the provider remains subject to the Agreement's direct-request channel because of where it's incorporated, not where its racks sit. SCX.ai and Australian-owned neoclouds are built to close that second gap, at the cost of a far smaller GPU catalog and none of the managed-service ecosystem AWS, Azure, and GCP customers rely on. The right call depends on what you're actually protecting against: an APP 8 cross-border disclosure obligation is satisfied by residency plus a solid contract. A hard requirement that no foreign government can compel access needs sovereignty, and today that means a much shorter list of providers with far less compute on tap.
GPU Cloud Providers in Australia: Hyperscaler and Sovereign Matrix
| Provider | Region | Hardware | Incorporation / CLOUD Act Exposure | Sovereign Claim |
|---|---|---|---|---|
| AWS | ap-southeast-2 (Sydney), ap-southeast-4 (Melbourne) | P5 H100 | US-incorporated; exposed under the Agreement | Residency only |
| GCP | australia-southeast1 (Sydney) | A3 High H100 | US-incorporated; exposed under the Agreement | Residency only |
| Azure | australiaeast | ND H100 v4 | US-incorporated; exposed under the Agreement | Residency only |
| SCX.ai | Equinix SY5, Sydney | ASIC (SambaNova partnership) | Australian operation | Residency and sovereignty |
| Sharon AI (with NVIDIA) | Multiple AU sites, ramping through 2027 | GB300 | Deploying, not yet a self-serve rental product | Announced capacity |
| Firmus Technologies | Melbourne, Tasmania, +3 planned | GB300 | Deploying, not yet a self-serve rental product | Announced capacity |
| Spheron | Global marketplace, 5+ providers | H100, H200, B200 | Not Australia-incorporated; no in-country node | Neither; global cost-efficient access |
AWS gives Australian teams two in-country regions, Sydney and Melbourne, which is unusual redundancy for a single country and useful if you need multi-region failover without leaving Australian soil. GCP and Azure each run a single Australian GPU region. The Sharon AI and Firmus rows are capacity under construction, not products you can provision against today; check back as their 2026 and 2027 milestones land. Spheron doesn't have an Australian node at all: for workloads where in-country placement isn't a regulatory requirement, mainly training on anonymized data and batch inference, it aggregates GPU capacity from 5+ providers globally at neocloud pricing well below any of the three hyperscalers' Sydney rates.
Australia GPU Pricing in 2026: Hyperscaler vs Neo-Cloud
Hyperscaler Australian regions carry the same premium over global neocloud pricing that shows up in every other developed GPU market, driven by managed-service overhead and lower regional competition rather than higher underlying hardware cost.
Spheron Live Pricing (as of 11 Aug 2026)
| GPU | On-Demand (per GPU/hr) | Spot (per GPU/hr) |
|---|---|---|
| H100 SXM5 | $3.98 | $2.10 |
| H200 SXM5 | $4.79 | $3.31 |
| B200 SXM6 | $9.36 | $5.34 |
| A100 80G SXM4 | $1.82 | $1.15 |
Pricing fluctuates based on GPU availability. The prices above are based on 11 Aug 2026 and may have changed. Check current GPU pricing → for live rates.
Australian hyperscaler H100 pricing runs $12-14/hr per GPU across AWS, GCP, and Azure's Sydney and Melbourne regions, broadly in line with their US and European list rates rather than a distinct APAC premium. Against Spheron's $3.98/hr on-demand H100, that's a 3-3.5x multiplier for the same hardware class. The trade you're making for that multiplier is in-country placement and the managed-service ecosystem, S3, BigQuery, SageMaker equivalents, tight IAM integration, that neither SCX.ai nor a global neocloud marketplace currently matches. For a wider view of on-demand pricing across the market, our GPU cloud pricing comparison covers 15+ providers globally.
Choosing a GPU Cloud Provider in Australia by Workload
Regulated personal data, hard sovereignty requirement. Health records, financial services data subject to APRA oversight, or government workloads where no foreign jurisdiction can be permitted to reach the infrastructure: SCX.ai's Equinix Sydney node is currently the clearest sovereign option, though its ASIC architecture and SambaNova partnership mean it's not a drop-in GPU replacement for CUDA-dependent pipelines. Confirm your framework runs on that hardware before committing.
Regulated personal data, residency sufficient. APP 8 disclosure obligations, not a sovereignty mandate: AWS Sydney or Melbourne, GCP australia-southeast1, or Azure australiaeast with a signed data processing agreement covering reasonable-steps compliance. Accept the hyperscaler premium as the cost of in-country compute plus managed services.
Training on anonymized data, cost efficiency priority. APP 8 doesn't apply to properly anonymized datasets, so residency isn't a constraint. An H100 SXM5 rental or B200 GPU rental through Spheron's global marketplace clears the hyperscaler premium entirely, with per-minute billing and no long-term commitment. This is the same architecture our Middle East GPU cloud guide and Europe GPU cloud guide recommend for teams in other strict-residency markets: keep the regulated data in an Australia-hosted storage bucket you control, and run the compute wherever it's cheapest.
Planning 2027 capacity, want to track the sovereign buildout. Sharon AI and Firmus Technologies are both scaling toward multi-hundred-megawatt GB300 capacity in Australia. Neither is a self-serve rental product yet. If sovereign, GB300-class compute is a hard requirement for a project on a 2027 timeline, these are the two deals to watch, alongside our GPU shortage 2026 analysis on how sovereign orders of this scale ripple through global GPU allocation.
For teams evaluating vendor security posture alongside data residency, our SOC 2 compliant GPU cloud providers guide and EU AI Act compliance guide cover the parallel compliance frameworks buyers in regulated industries are usually weighing at the same time.
This is a technical summary, not legal advice. The Privacy Act, the CLOUD Act Agreement, and the National AI Plan's forthcoming Australian Standards for AI are all live regulatory areas in 2026; sector-specific guidance from APRA, the OAIC, and the new federal Office of AI carries more practical weight than the general rules in this post.
Training on anonymized data or running batch inference that doesn't require in-country placement? Spheron gives Australian AI teams access to H100, H200, and B200 GPUs from 5+ providers globally at neocloud pricing, with per-minute billing and no hyperscaler procurement cycle.
H100 GPU rental → | B200 on Spheron → | View all GPU pricing →
Frequently Asked Questions
It let law enforcement in each country request electronic data directly from providers incorporated in the other's jurisdiction, without going through the slower mutual legal assistance treaty process. It was signed on December 15, 2021 and took just over four years to enter into force. It applies to a provider's incorporation, not where its servers sit, so AWS, Azure, and GCP's Sydney and Melbourne regions carry the same exposure as their US regions.
Not automatically. APP 8 requires you to take reasonable steps, usually an enforceable contract, to ensure an overseas recipient handles personal information consistently with the Australian Privacy Principles, and you stay accountable if that recipient mishandles it. A December 2024 reform added an exception for prescribed countries and binding schemes. Training on anonymized data sidesteps APP 8 entirely, since it only governs personal information.
SCX.ai launched Australia's first sovereign AI inferencing node on January 29, 2026, at Equinix's SY5 data centre in Sydney, built on ASIC hardware through a SambaNova Systems partnership rather than GPUs. It targets financial services, healthcare, and government workloads that need data to stay inside Australian borders, and it supports Project MAGPiE, an Australia-focused language model.
Sharon AI signed a six-year deal with NVIDIA in June 2026 for up to 40,000 GB300 GPUs across 72MW of new capacity, targeting 55,000-plus total GPUs and 132MW by mid-2027. Firmus Technologies' Project Southgate scales from an initial AU$4.5 billion investment toward A$73.3 billion and 1.6GW across five sites by 2028, with 18,500 GB300 GPUs at its Melbourne site alone.
No. Data residency means your data physically sits inside Australia, which AWS Sydney, Azure australiaeast, and GCP australia-southeast1 already satisfy. Sovereign AI adds a further requirement: that the infrastructure, ownership, and operational control also sit outside foreign jurisdiction, which is what SCX.ai and the Australian-owned neoclouds are built to offer. A hyperscaler region can give you residency without sovereignty.





