Private AI and public cloud AI describe different custody and operating models. Neither is automatically safe. A law firm should choose the boundary after classifying the information, defining the workflow, reviewing client and professional duties, and deciding who will administer the system.

Compare the operating models

Question Public cloud service Private or firm-controlled system
Setup Usually faster Requires design, hardware or private hosting
Updates Vendor-managed Firm or provider-managed
Data custody Governed through vendor architecture and contract Greater direct control, with local duties
Scale Usually elastic Limited by purchased capacity
Support Product support model Requires named technical operators
Failure burden Vendor and connectivity dependence Local power, hardware, backup, and recovery

“Private AI” can refer to several architectures. A dedicated cloud environment, firm-managed server, local workstation, isolated network, and fully air-gapped system do not provide the same custody or operating model. Ask for a diagram of the exact system rather than accepting the label.

Choose by information class

Public tools may fit public research and sanitized administrative work. Approved enterprise cloud services may fit more sensitive workflows after contract, privacy, security, and professional review. On-premise or isolated systems may fit restricted firm knowledge when the firm can operate them properly. Air gaps suit narrow cases where isolation justifies substantial friction.

Compare the boundary in full

Decision factor Public cloud may fit when… Private or local may fit when…
Information The approved plan and contract fit the information class External processing conflicts with the required boundary
Permissions Existing identity and document controls can be enforced The firm needs a separately administered collection
Connectivity Reliable access is available The workflow must continue inside a local or isolated environment
Change speed Managed updates and elastic capacity are valuable The firm needs tighter control over updates and validation
Operations The firm prefers vendor-managed infrastructure The firm has named security, backup, model, and application operators
Client terms The proposed service can meet reviewed commitments A client or matter requires stronger custody or isolation
Economics Variable use and subscriptions fit demand Stable demand justifies hardware, hosting, and specialist support

This comparison does not decide whether a proposed use complies with the firm’s duties. It identifies the evidence the firm needs for that decision.

Questions for a public cloud service

Ask about the exact business or enterprise plan, not the consumer product in general:

  • whether customer content is used to train models;
  • processing and storage locations;
  • retention, deletion, and backup behavior;
  • subprocessors and support access;
  • encryption and identity controls;
  • logs available to firm administrators;
  • connector permissions;
  • incident commitments;
  • data export and service termination;
  • how model or feature changes are communicated.

The firm must confirm these answers in current documentation and agreements. Marketing pages are not a substitute for the reviewed terms.

Questions for a private system

Private custody moves questions inward:

  • Who patches the operating system, models, retrieval software, and dependencies?
  • Who administers users, matter access, secrets, and service accounts?
  • Where are backups kept, and has restoration been tested?
  • How are logs protected and reviewed?
  • How does the firm test a new model or knowledge collection before release?
  • What happens during power, storage, network, or hardware failure?
  • Which provider personnel can access the environment for support?
  • How are deleted matter files removed from indexes and backups?
  • What capacity is available during a large review?
  • Who responds after an incident at 2 a.m.?

If the firm cannot name the operator, the private architecture is not fully designed.

Run the same acceptance tests

Test access by role and matter, source traceability, deletion, logs, refusal behavior, backup, restore, incident handling, and total review time. Apply the NPC AI advisory when personal data is involved.

Use the same representative documents and acceptance standard for both options. Otherwise the comparison rewards whichever vendor received the easier test. Include unsupported questions, revoked access, superseded sources, deletion requests, and a simulated service interruption.

A practical decision record

The managing partner should receive a short record containing the workflow, information class, considered architectures, reviewed duties, key vendor or operator evidence, acceptance-test result, residual risks, responsible owner, review date, and approval conditions.

The record should also state what would force reconsideration, such as a new client restriction, vendor-term change, model update, incident, failed restore test, or expansion to a more consequential use.

Private custody creates responsibility. Cloud convenience creates dependency. The right answer is the boundary the firm can defend and operate. Continue with the guide to an AI-native law firm and Aizen’s Private Off-Grid AI for Law.

A mature decision may use more than one boundary. Public research, approved cloud assistance, and a restricted private knowledge system can coexist when the firm separates their purposes and information clearly. Architecture follows the work. It should never become an excuse to move information across boundaries that the firm has not approved.

Source ledger

Sources used and checked

Verified July 13, 2026. Links may change after publication.

  1. Guidelines on AI systems processing personal dataNational Privacy Commission, accessed July 13, 2026
  2. AI Risk Management FrameworkNational Institute of Standards and Technology, accessed July 13, 2026