What Counts as Private AI?
"Cloud AI" is three different things. Match each kind of data to the lowest tier that protects it.
The everyday ChatGPT, Claude or Gemini. Inputs may be logged or used for training. Public data only.
A business tier or API under a DPA with no-training, zero-retention terms. Confidential data, if that contract is genuinely in place.
Open models on your own hardware, no third party. Your most sensitive data, and the simplest route when it must stay local.
Public material is fine in any tier. Sensitive data never goes into a consumer tool.
Moving from a consumer tool to a contracted one changes your data-control position substantially. The contract is only the start: personal data still needs the right GDPR and transfer safeguards.
When to use Before anything sensitive goes near a chatbot.
Read the full post →