The risk of using AI in a confidentiality-sensitive business comes down to one question: where does your data actually go? There are four practical levels of protection, from least to most secure — a public chatbot that trains on your inputs, a provider that contractually won’t train on them, a cloud instance hosted in Australia, and a model running entirely on hardware you own. Each level keeps the data closer to home. Knowing which one you are on is the whole game.
Most businesses pasting client details into an AI tool have never asked the question. The convenience is immediate and the exposure is invisible, which is exactly why it spreads. For a law firm, an accountant, a medical practice or anyone bound by confidentiality, the gap between level one and level four is the difference between a useful tool and a reportable breach.
Level one: a public chatbot that trains on what you type
The least secure option is a consumer AI account where your conversations can be fed back into model training — and many users have never opened the setting that turns this off. Consumer plans treat that data differently from business agreements. Anthropic states that for its consumer products such as Claude Free, Pro and Max, “we will use your chats and coding sessions (including to improve our models) if” you allow it in your settings (Anthropic Privacy Center).
The exposure here is twofold. Your confidential text may be retained and used to improve a system millions of strangers query, and it sits on overseas servers governed by someone else’s terms. For regulated work this is the level that quietly creates problems, because the person typing usually believes the tool is private when the default settings say otherwise.
Level two: a provider that contractually won’t train on your data
Level two is a business or API tier where the provider contractually commits not to train on your inputs — a real improvement, but your data still leaves the country. The commercial terms differ from the consumer ones. OpenAI states that “as of March 1, 2023, data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in)” (OpenAI). Anthropic gives the same assurance for its commercial products.
“By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models.”
This closes the training risk, but not the location one. Under Australian Privacy Principle 8, an entity that discloses personal information to an overseas recipient “is accountable for any acts or practices of the overseas recipient in relation to the information that would breach the APPs” (OAIC). The liability follows the data offshore, even when you have done the paperwork.
Level three: a cloud AI instance hosted in Australia
Level three keeps the data in Australia by running the model inside a cloud region physically located here, so it never crosses a border. Major cloud providers now offer models hosted in Australian regions, with commercial terms that keep your inputs out of model training. You get a managed, capable model with the cross-border question answered — the data stays in-country, and the provider commits not to learn from it.
For many Australian businesses this is a sound, pragmatic choice. The trade-off is that the model still runs on infrastructure you rent rather than own, governed by a provider’s account model and shared-responsibility terms. It resolves the cross-border problem, but the data still lives in a third party’s environment — which for the most sensitive work is one boundary too many.
Level four: a local AI that never leaves the building
The most secure level is a private model running on hardware you control, where confidential data never leaves your premises at all. This is the Fortress approach. There is no provider account and no overseas region — the model, the documents it reads, and the answers it returns all stay inside your own walls. For a firm whose entire obligation is keeping client information confidential, this is the only level that removes the exposure rather than contracting around it.
The objection used to be capability and cost, and that objection has weakened. Capable open-source models now run on a single workstation GPU, which puts a genuinely private deployment within reach of a small practice rather than only an enterprise. Paired with a retrieval system that gives the model access to your own files, you get the working power of a modern assistant with the data discipline of an offline archive. This is the level our private local AI work is built around, because for confidentiality-sensitive industries the safest place for the data is the only place that counts.
Which level does your business actually need?
The right level is the lowest one that fully covers your obligation — and for confidentiality-bound work, that is usually higher than people assume. The four-level ladder reflects the reality that data breaches are common and expensive: Australian organisations reported 595 notifiable data breaches in the second half of 2024 alone, with health service providers the single most-breached sector at 20 per cent of all notifications (OAIC).
A marketing team drafting public copy is fine at level two. A clinic, a law firm or an accountant handling privileged client records belongs at level three or four, where the data either stays in the country or never leaves the building. The levels are not a hierarchy of quality — they are a hierarchy of where your data lives, and the correct answer is set by your duty of confidentiality, not by which tool is easiest to open. Choose the level deliberately, and the controls compound: data discipline, compliance and client trust reinforce one another instead of working against the convenience.
If you are not sure which level your current setup sits on, that is the first thing worth establishing. We can map where your data goes today and what it would take to move up a level — start a conversation or see how we scope a build.
Frequently asked questions
Is it safe to put confidential client data into ChatGPT or Claude?
Not on a consumer plan by default. Consumer tiers may use your conversations to improve the underlying models unless you change the setting, and the data sits on overseas servers. For confidentiality-bound work — law, medicine, accounting — the safe options are a commercial agreement that contractually excludes training, an AI instance hosted inside Australia, or a private model running on hardware you control.
What is data sovereignty and why does it matter for AI?
Data sovereignty means your data is subject to the laws of the country it physically sits in. It matters for AI because most public tools process your inputs on overseas servers. Under Australian Privacy Principle 8, an entity that sends personal information overseas remains accountable for how the overseas recipient handles it, so the legal responsibility does not stop at the border even when the data does.
What is a local or private LLM?
A local LLM is a language model that runs entirely on hardware you own or control, rather than on a provider’s cloud. Your prompts, your documents and the model’s answers never leave your premises, which removes both the training risk and the cross-border disclosure risk. Modern open-source models run on a single workstation GPU, making a private deployment practical for small businesses, not only large enterprises.
Does a cloud AI hosted in Australia solve the confidentiality problem?
It solves the data residency problem, which is a major part of it. Running a model in an Australian cloud region keeps the data in the country and, with major providers, contractually out of model training. The remaining trade-off is that the data still lives in a third party’s infrastructure under shared-responsibility terms. For the most sensitive work, a fully local deployment is the only option that keeps the data entirely in your control.
Read more
Let's compound
Tell us where growth stalls.
One team that connects your website, marketing and operations — and compounds the results. Pick whichever way is easiest to start.
Australian-based · Founder on every project