Most of what a small practice does all day is safe to put in an ordinary cloud AI tool. The part that is not safe is usually smaller than people fear, and it is defined by the data you paste in rather than the task you are doing. This post sorts your work into four buckets, and only the fourth needs a machine that never leaves your office.

The sort takes an afternoon and it settles most of the argument before you have looked at a single product. None of this is legal advice. If you work under HIPAA, a bar rule or a client contract, your own counsel has the last word on your practice.

Everyone asks the wrong question

Cloud or local is a question about infrastructure, and almost nobody writing about it is writing for you. The pages that rank come from enterprise infrastructure vendors, from compliance publishers and large law firms, from developers sharing a build, and from vendors with one product to sell. Four groups, four agendas, none of them addressed to a six-person practice trying to decide something this week.

The question that decides it is much narrower, and it has nothing to do with where the servers live. Which of the things you do all day are safe to paste into a chat box? That is a sorting job on your own work, and once it is done the tooling question mostly answers itself.

Bucket one: nothing sensitive in it at all

Marketing copy. Job ads. A first draft of a policy. An email to a supplier. Notes from a meeting with nobody's name in them. None of this contains a client, patient or customer identifier, and an ordinary cloud tool is the right home for it.

Even the strictest professional guidance agrees. ABA Formal Opinion 512, which is about as cautious as this subject gets, says there are uses "when client informed consent is not required because the lawyer will not be inputting information relating to the representation," and gives idea generation as its example. If that holds for a lawyer, it holds for your job ad. This bucket is larger than most owners expect, because nobody has ever counted it. It covers most of the everyday tasks AI can take over.

Bucket two: sensitive, but the identity can come out

Some work is about a real person, yet the useful part survives taking the person out of it. A billing dispute you want a second read on, or a difficult letter you are struggling to word. Strip the identifiers and what is left is often still enough to get help with.

The rule underneath this is real, not a workaround. Under 45 CFR 164.514(a), health information "that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual is not individually identifiable health information," which puts it outside the Privacy Rule. Two things catch people. It applies to the whole thing you paste, free text included, so one stray detail in a paragraph undoes it. And the regulation adds that you must not have "actual knowledge" the information could still identify someone, which is a real limit in a small town or with an unusual presentation. The federal guidance on de-identification says the residual risk is very small but "it is not zero."

Exhibit 1

Sort the task by what you would paste, not by what the task is called.

no yes yes yes no no Does the text you would paste identify a client or patient? Is it still useful with the identifiers stripped out? Can you move onto a business account and sign for it? One: nothing sensitive An ordinary cloud tool is fine Two: identity comes out Strip it, then paste the rest Three: regulated Right tier, signed paperwork Four: it stays put Where a local model fits
Note: this is our own framework for running the sort, not a survey finding and not legal advice. The point of the path is that the same task can land in different buckets depending on what you would actually type.

Bucket three: regulated, and fixed by a tier plus paperwork

This is where most readers land, and it is the bucket almost nobody writes about. The work genuinely involves protected information, you cannot strip the identity out without ruining it, and you still want the help. The fix is not a different building. It is a different account.

All five major providers now publish, in writing, the same three commitments: they do not train on your data, they hold it for a defined period or not at all, and they will sign a business associate agreement for healthcare. In every case those terms attach to the business, enterprise or developer product rather than the consumer subscription, and most of them need an approval step before they switch on. None of them apply by default when someone signs up with a credit card, which is exactly how most practices first met these tools.

The gap between the two tiers is not marketing. Google prints this in bold in its own terms for the unpaid tier: "Do not submit sensitive, confidential, or personal information to the Unpaid Services." That is the vendor telling you which bucket its free product belongs in. What follows from there depends on your obligations, so read the version written for your work: if you handle patient records, or if you owe clients confidentiality. Two more trades carry a federal rule of their own on top of whatever the vendor signs: what section 7216 asks of a tax practice, and the two rules that govern advisory firms.

Vendor tiers and the scope of what each provider will sign, last-verified: 2026-08-13. These lists move fast. One of the vendor pages behind them was stamped as updated within the last two weeks, so check the provider's own current page before you rely on any of this.

Bucket four: it cannot leave the building

The smallest bucket, and the one the whole industry writes about. Four situations put you here honestly: a contract or a client that forbids third-party processing at all; information sensitive enough that the residual risk is unacceptable no matter what anyone signs; someone already on staff who runs and patches servers; or a task narrow and repetitive enough that a smaller model does it well enough.

Three of those four are about your obligations and your staffing rather than the technology. If none describes you, bucket four is not where your work belongs, however uneasy the subject makes you feel. If one does, the trade is real and worth understanding before you buy anything, which is the subject of what running AI in your own office actually involves.

Exhibit 2

Four groups write about this, and none of them is writing to you.

Who writes about this, and what it leaves you with Enterprise infrastructure vendors Selling capacity. Assumes a CIO and a seven-figure budget. Compliance publishers and large firms Client alerts. Diagnose the risk, never resolve the workflow. Developers and enthusiasts Sharing a build. Hardware detail, and no business decision. Point-solution vendors Selling one tool. The answer is always that tool. A six-person practice deciding this week Nobody is writing this one, which is why this page exists.
Note: the four groups come from our own review of what currently ranks on these searches, read 2026-08-13. It describes who publishes, not how good any individual page is.

No bucket fixes accuracy

Privacy and accuracy are separate properties, and sorting your work well solves only the first. A model running on a machine in your own office will invent a case citation or a drug interaction exactly as readily as one running in a data centre. Whichever bucket a task sits in, somebody who knows the subject still has to read the output before it goes anywhere.

Run the sort this week

Write down the ten things you would most like AI to take off your hands. Beside each one, mark whether the text you would type contains a client or patient identifier. For the ones that do, mark whether the task survives having those identifiers removed. You now have your four buckets, and the shape of the answer is usually visible on the page.

If the fourth bucket comes back empty, that is a real result and not a sign you have filled the sheet in wrong. Most of the cloud-or-local argument disappears at that point, and what is left is a shopping question you can answer calmly. Working through that sheet is the first hour of deciding this with you.

Common questions

Is private AI suitable for small businesses?

For a narrow set of them, yes, and for most of them the honest answer is that a business-tier cloud account with the right contract gets you the same protection with far less to maintain. Private AI suits a business that already has someone running servers, or one whose contracts forbid outside processing outright. Everyone else tends to buy a machine and inherit a second job.

Which is better for data security, cloud AI or AI you run yourself?

Neither wins on its own. A machine in your office removes the outside vendor and replaces it with a server you now have to patch, back up, lock down and replace. A business-tier cloud account keeps the vendor but gives you written terms, a signed agreement and someone else doing the maintenance. The safer choice is the one your practice can realistically keep running.

Is cloud AI more cost-effective than AI in your own office?

Usually yes, once you count the machine, the electricity and the person who looks after it. Cost is a poor reason to bring AI in-house. The reasons that hold up are contractual and practical ones, which is what bucket four is built on.

Start a conversation

All notes Start a conversation