Why your AI should live in your office
The foundational argument, with the parts that do not flatter it left in.
Zavier Taylor
The problem nobody at your firm is saying out loud
Your staff are already using AI. Not officially, and possibly not with permission, but the associate drafting a letter, the junior summarising a report, the accountant cleaning up a spreadsheet. They are pasting real work into ChatGPT because it is genuinely useful.
Every time they do, a piece of your clients' confidential information leaves the building and lands on a server in another country, owned by a company you have no contract with.
For most businesses that is a vague discomfort. For a law firm or an accounting practice it is a professional-conduct problem. The New Zealand Law Society's guidance on generative AI is explicit: lawyers remain fully responsible for what these tools do with client data, must not feed client or personal information into external AI tools without proper care, and must vet exactly where data goes, whether it is stored, and whether it trains the model. (NZ Law Society, generative AI guidance)
You cannot meet that standard with a tool that sends everything to California.
The usual answers, and why they do not satisfy
"We have banned it." Bans do not work. The tool is too useful and staff route around them. What you have lost is visibility, not risk.
"We use the enterprise version." Better, genuinely. The data still leaves your building, still crosses a border, which is a live issue under Privacy Act 2020, IPP 12, governing personal information sent overseas, and you are still trusting a retention promise you have no way to inspect. (Privacy Act, IPP 12)
"We will wait until it is safe." Meanwhile your competitors are getting faster and your staff are already using it unofficially. Waiting is not neutral.
The other answer: do not send the data anywhere
Run the model on a computer inside your own office, on your own network. Your documents, your client information, and everything the system does with them stay in the building. No cross-border transfer. No third-party retention. Nothing to trust, because the data physically never leaves.
This was not practical two years ago. The models you could run privately were poor and the hardware was expensive. Both of those changed across 2025 and 2026. A single quiet box roughly the size of a Mac mini now runs a model good enough for the everyday work a professional office actually does: reading documents, drafting, summarising, answering questions about your own files.
How good, exactly, and where it still falls short, is the subject of the frontier–local gap. That piece is built on measurements rather than my word for it, and it includes the numbers that argue against me.
What you actually get, in three layers
- A private assistant. A chat tool your staff reach from a browser, which knows only your files and never phones home.
- Trained on your work. It can be taught your house style, so it drafts in your firm's voice, structure and standard clauses rather than generic AI prose. Whether you need that at all is a genuine question, and I have argued both sides in retrieval or training.
- Working around the clock. With no per-use meter it can run overnight, reading every new file, triaging the inbox, keeping the index current, for the cost of the electricity.
If you want the component-by-component version, what actually runs on the box is the full inventory, including the parts that are deliberately absent.
Where this is not the right answer
I would rather say this now than have you discover it later.
It is not about saving money. Cloud AI is cheap and getting cheaper. If somebody sells you a private box on cost savings, check their arithmetic. I did, in falling prices, rising bills, and the honest case is a fixed, predictable cost rather than a lower one.
The hardest work still favours the frontier. For long, complex, multi-step reasoning the large cloud models remain ahead. A private box is excellent for the bounded, repeatable majority of the work. For the hardest fraction there is an optional and controlled route out to a frontier model, but only if you choose it, and never for privileged material.
It is not for everyone. If your firm has no real confidentiality pressure and no appetite for always-on automation, an off-the-shelf business subscription is probably fine, and I will tell you so rather than sell you a box.
The bottom line
The question is not "is AI safe?" It is "where does your clients' information go when your staff use it?" Right now, for most firms, the honest answer is: somewhere you do not control.
Putting the model in your office changes that answer to nowhere it should not be. That is the whole idea.