Use AI without giving up control of what it knows.

Some organisations cannot send their records to somebody else's cloud. Not reluctant to, cannot. Confidentiality is part of what their clients are paying for, and a third-party processor is a category of risk they are not permitted to accept.

That is an architecture problem, not a reason to leave AI alone. The question is which work can safely leave the organisation and which cannot, and those are rarely the same answer twice.

When this is the right thing to ask for
  • Client confidentiality or professional privilege is involved.
  • A small team holds material with consequences far larger than the team.
  • Decades of records would be useful if anyone could find anything in them.
  • An external model is the capable option and also the uncomfortable one.
  • Data residency or cross-border obligations constrain the choice.
  • The obligation is structural rather than a preference to be traded away.

Why this is an architecture question

The instinct in a confidential environment is to ban the tools, and the result is predictable: capable people use them anyway, on personal accounts, with no logging and no boundary. Prohibition tends to produce exactly the exposure it was meant to prevent.

The opposite instinct, connecting whichever model is most capable, moves the problem rather than solving it. A request passes through more companies than the interface suggests, and in an organisation where confidentiality is the product, that is a category of risk rather than a clause to negotiate.

Between those two is a design question with real trade-offs. Running models privately costs more and usually performs less well. Controlled external routes are capable and carry supplier exposure. Most organisations need both, split according to what the material is rather than according to which option somebody prefers.

What the decision actually turns on

What the obligation really is

Contractual, regulatory, professional or reputational. They point at different architectures, and conflating them produces expensive over-engineering.

What may leave and what may not

Usually not a single line. Classification decides routing, and routing decides most of the cost.

Where the models run

On your own hardware, on cloud set aside for you, through a controlled external route, or some mix of the three. Each is a real trade between capability, cost, control and who you end up depending on.

Who can reach what

Access that follows the entitlements people already have, rather than creating a second set that nobody maintains.

What is written down

Retention, logging, and being able to show afterwards which document an answer came from rather than paraphrasing it into something plausible.

How you get out

What replacing a provider would involve, before the provider becomes the only option.

What you end up holding
  • A classification of the work: what can use an external model, what needs a controlled route, and what should not leave at all.
  • An architecture that follows the obligation rather than the fashion, with the trade-offs stated rather than assumed.
  • The cost picture, which behaves nothing like hosting and surprises people.

Local is not automatically safer, open weights are not automatically private, and a private model is not automatically compliant. Anyone who tells you otherwise is selling something.

Why me for this

One case on this site describes an archive of decades of confidential records made searchable with nothing leaving the premises. Sector named, nothing else.

Read how that was built

Related

The useful time for an independent view is before the decision becomes difficult to reverse.

Two or three lines are enough: what is happening, what decision is coming, and when it matters. You do not need to know which kind of engagement this is. LinkedIn is the single route in, on purpose.