Private is a design decision
Where does the model run? Which documents can it read? What leaves the device or network? Who can see logs? The answers depend on the chosen model, tools and deployment—not on the label “AI”.
Bring the constraints into the design
A useful readiness discussion covers hardware, representative tasks, data permissions and the level of reliability needed.
- Inputs: hardware limits, permitted example data, access roles and desired tasks.
- Deliverables: a bounded design, an agreed prototype or application, evaluation examples and operating guidance.
- Decide explicitly whether external providers, telemetry, model downloads or updates are permitted.
Evaluate before extending access
Start with a small permitted dataset, test representative questions and failure cases, review answers and source grounding, then decide what access is justified. Human review remains appropriate for consequential decisions.
Know the limits
No blanket promise of offline operation, perfect answers or automatic confidentiality applies to every option. New hardware, model licensing, specialist security assessment and ongoing operations are separately scoped.