Why a dental practice manager asked me whether AI could run locally
Thursday, 6.10pm, a three-surgery dental practice in Bristol. The last patient has gone, the autoclave is running, and the practice manager is writing a referral letter to an oral surgeon from the dentist's clinical notes. She has done this roughly 400 times. Tonight she opens a free chatbot on her phone, pastes the notes in — name, date of birth, medical history, medication, the lot — and asks for a referral letter.
Nine seconds later she has one, and it is better than the template. Then she stops, because something about it feels like the moment before you realise you have left the front door open. She sent me the question that evening: "Is that allowed? And can I run AI locally instead, so it never leaves the practice?"
It is the right question, and the honest answer has three parts. This article is those three parts.
How common the Thursday-evening paste is
Very. The LayerX Enterprise AI & SaaS Data Security Report (October 2025) found that 77% of employees paste data into generative AI prompts, and that 82% of those pastes come from personal accounts the business cannot see. The average is 14 pastes a day, at least 3 of them containing sensitive data.
It costs real money when it goes wrong. IBM's Cost of a Data Breach Report 2025 found that one in five organisations studied had suffered a breach linked to "shadow AI" — tools staff adopted without anyone approving them — and that those breaches cost $670,000 more than average, roughly £500,000. Some 63% of breached organisations had no AI governance policy at all.
The UK picture is the same shape. The government's Cyber Security Breaches Survey 2026 found 31% of businesses using, adopting or considering AI, and of those, only 24% with any process to manage the risks. Meanwhile the ONS reports AI use in UK businesses with 10 or more staff has nearly tripled since late 2023, to around 35%. The tools arrived faster than the thinking.
Why it matters more in a dental practice than a design studio
Because clinical notes are health data, and health data is special category data under UK GDPR. Pasting it into a consumer chatbot on a personal account means a third party you have no contract with is now processing it, in a country you have not checked, under terms nobody at the practice has read. The letter being good does not change any of that.
The tool itself is not the problem. The MHRA's July 2026 guidance confirms that AI used to transcribe, summarise and draft correspondence for a clinician to review is not a medical device, and the clinician stays responsible for what goes to the patient. So drafting a referral letter with AI is fine. The whole question is where the data goes while it drafts — which is exactly what "can I run AI locally" is really asking.
The three questions hiding inside the one
When a business owner asks whether they can run AI locally, they are asking three things at once, and the guides online only answer the first.
- Is it technically possible? Yes, on surprisingly ordinary hardware. Section two.
- Is it good enough to be useful? For most office work, yes, with honest caveats. Also section two.
- Can it work for a team, not just one laptop? Yes, but that is a different project from a download, and it is the part everyone skips. Sections two and three.
