More and more firms want to use artificial intelligence to find information across their files. But as soon as documents are covered by professional secrecy, one question dominates: where does the data actually go?
The real risk: data leaving the building
Most consumer AI tools send your queries, and often your documents, to remote servers. For a firm, that means exposing confidential information to a third party, with the obvious professional and contractual consequences.
The questions to ask any vendor
- Where are the model and the data hosted: on your premises, or in the cloud?
- Do documents leave your network, even temporarily?
- Does the vendor store, log or reuse your queries?
- Is there a data processing agreement (DPA) and the option to audit?
Why on-premise processing removes the obstacle
An AI installed on your own hardware, with no outbound connection, answers that constraint in the most direct way: the processing perimeter is the firm’s own, and it can be audited on site. That is why professions bound by secrecy adopt it most often.
Before adopting an AI, demand a written answer to these four questions. Depending on your obligations, an installation on your premises or dedicated hosting governed by a processing agreement can both work: what matters is that the choice is documented and defensible, not inherited.
