What Is Private AI? Keeping Client Data In-House in the Age of ChatGPT

Published on 5 October 2026
Business AI Agents logo
Dr. Shadi Ghaith Founder, Business AI Agents ·

What is private AI? It is AI that runs where only your business can reach it, so the documents and questions you give it are never sent to, kept by, or trained on by an outside provider. In practice that means a model on your own machine or in a ring-fenced environment, rather than a public chatbot.

Lettings negotiator at an estate agency desk after hours, a passport and tenant ID papers beside her laptop
Six o'clock, one tenant application, and a free chatbot one paste away.

Why an estate agent asked me what private AI is

Thursday, 6.10pm, a ten-person sales and lettings agency. A negotiator has a tenant application to sign off before the landlord rings at nine: three payslips, six months of bank statements, a passport scan and a reference letter. She pastes the lot into a free chatbot and asks whether the rent is affordable. The answer is tidy and correct. Then she looks at what she has just sent, and to whom.

Her director asked us the following week: "What is private AI, and do we need it?" Here is the plain answer.

How AI affects data privacy in a ten-person agency

Mostly through the quiet paste. Microsoft's 2024 Work Trend Index found 78% of AI users bring their own tools to work, rising to 80% in small and medium businesses. Cyberhaven (2026) found 39.7% of the data employees move into AI tools is sensitive. The UK government's Cyber Security Breaches Survey 2025/26 adds the local picture: of businesses using or considering AI, only 24% have security practices in place for it.

An agency is a concentrated case. Money laundering checks mean passports and source of funds for every buyer, under HMRC supervision; lettings adds referencing and Right to Rent copies. The sector has seen what happens when that material leaks: in 2019 the ICO fined a London agency £80,000 after passports and bank statements for 18,610 people were left exposed on a server.

Where a pasted document actually goes

Further than most people assume. Consumer ChatGPT may train on conversations unless a setting called "Improve the model for everyone" is off. Google keeps Gemini chats chosen for human review for up to three years, even after you delete your activity, and asks you not to enter "confidential information that you wouldn't want a reviewer to see". Since August 2025, consumer Claude users who opt in to training have their chats retained for five years. None of this is sinister. It is simply someone else's computer, under someone else's rules.

Need Help with AI Solutions?

Get in touch with our team or try our AI assistant.

Two offices side by side: one sends a document up to a cloud server, the other keeps it on a padlocked machine inside
Public AI on the left, private AI on the right. The difference is where the arrow stops.

What is private AI, and how does it work?

Private AI is any setup where the model processing your data is under your control, or under a contract that rules out training and limits retention, so nothing you type becomes someone else's asset. It is a spectrum rather than a product: the more sensitive the material, the further towards your own building the model should sit.

The National Cyber Security Centre drew the same spectrum in 2023, advising against "sensitive information in queries" to public models and saying self-hosted ones "may be appropriate for handling organisational data". Self-hosting works because open-weight models such as Llama, Gemma and OpenAI's gpt-oss can be downloaded and run on your own hardware.

Type of AIWhere your data goesTrained on your data?Fits
Public chatbot (free or personal plan)The provider's servers, usually abroadOften, unless switched offBrainstorming, nothing personal
Business-tier cloud AIThe provider's servers, under a business contractNo, by defaultGeneral office work, with a vendor check
Private AI on your premisesA machine in your buildingNeverID documents, client files, anything regulated

What is data privacy in AI, in plain English?

It is the old data protection rules applied to a new tool. The ICO's AI guidance puts the core of it in one line: "you only process the personal data you need for your purpose". It also expects a data protection impact assessment (a written risk check) in "the vast majority of cases", and holds senior management accountable. The guidance is under review after the Data (Use and Access) Act 2025; the principles have not moved.

What private AI does not fix

Three rising platforms: an open chat bubble, a cloud with a shield and contract, and an office with its own AI machine
Three levels of privacy. Each step up keeps more of the data inside your walls.

It does not stop a model getting things wrong; the negotiator still checks the sum. It does not replace the impact assessment, only shortens it. And a home-made server left open to the internet is less private than a reputable cloud service.

Need Help with AI Solutions?

Get in touch with our team or try our AI assistant.

Four estate agency staff at laptops, each linked to one compact private AI machine on a shelf in the office
One rented machine on a shelf, shared by the whole office, with every document staying on it.

How we set up private AI for an estate agency

Our Local AI service is private AI at the far end of that spectrum: a dedicated machine, rented to the business rather than sold, installed on its network and running open-weight models. Staff sign in with their Microsoft 365 or Google accounts and use a ChatGPT-style assistant that sends nothing outside. The wider case for private AI for UK firms, and the hardware basics, are in our guide to running AI locally.

Agency taskPersonal data involvedWhere it runs now
Tenant affordability summaryPayslips, bank statementsLocal AI
Buyer source-of-funds file noteID, statements, gift lettersLocal AI
Answering questions on tenancy agreements and the office manualSome names and addressesLocal AI, in a shared document space
Property descriptions and social postsNoneAny tool the team likes
Viewing requests by phoneName and numberCloud AI Receptionist

We size the machine, install it, import documents with access rules (lettings sees lettings, sales sees sales), train the team and keep the models updated. The agency stays the data controller; we are a processor only for the support access it grants us, under a written agreement.

What an AI policy should include regarding data privacy

A tool without a rule just moves the quiet paste elsewhere. The NCSC's guidance on shadow AI (staff using AI the business has not approved) favours approved alternatives over bans. The one-page policy we write with clients covers five things:

Policy itemWhat it says at an agency
Approved toolsLocal AI for client documents; any tool for listings copy
Red lineNo ID, financial or tenant documents in public chatbots
Named ownerOne director signs off new AI uses, with an impact assessment
Human checkingA person checks anything before it reaches a client
RetentionAI outputs follow the rules of the file they came from

Our longer take is in what AI governance means for a small business. The honest limit: on-premise models are slower than the largest cloud ones and a weaker sparring partner on hard reasoning. For an agency, that matters far less than where the passports go.

Need Help with AI Solutions?

Get in touch with our team or try our AI assistant.

Questions UK businesses ask about private AI

Frequently asked questions

What is private AI?

AI that runs where only your business can reach it: on your own machine, or in a ring-fenced environment under a contract that rules out training. Your documents are not kept or trained on by an outside provider, which free chatbots cannot promise.

What is data privacy in AI?

Ordinary data protection applied to AI tools: knowing what personal data goes in, where it is processed, how long it is kept and whether it trains the model. In the UK that means UK GDPR and the ICO's guidance.

How does AI affect data privacy?

Mostly through what staff paste in. A document put into a public chatbot is copied to the provider's servers, may be kept for years and may train the model: a second copy outside your control.

How can organisations ensure data privacy when using generative AI?

Give staff an approved tool for sensitive work, write a red line for public chatbots, run an impact assessment before new uses, and keep a human checking outputs. For confidential documents, private AI on your premises removes the third-party question.

Is ChatGPT private?

Not on free and personal plans, which can train on conversations unless you switch it off. Business tiers are not trained on by default but still process data on OpenAI's servers.

Is private AI the same as on-premise AI?

On-premise AI is the most private form of it. Private AI also covers ring-fenced cloud setups under strict contracts. The difference is where the machine sits: on your premises, nobody outside the business ever holds the data.

Where to start

List the five documents your team would most like AI to read, and mark which hold personal data. That tells you which tasks can stay in the cloud and which need a private home.

Back to Thursday, 6.10pm. Same negotiator, same application. She drops the payslips and statements into the lettings space on the office machine, gets the affordability summary, checks the sum and saves it to the file. The passport never left the building. If you would like to know whether private AI fits your business, tell us what you would want it reading, or ask the chat agent on this page.