Skip to content

Private AI vs public AI tools: what business owners need to know

6 min read
Friendly toy robot sorting data blocks between a locked private box and a cloud tray, representing private AI and public AI tools

A lot of small businesses are already using AI, whether they have an AI strategy or not.

Someone asks ChatGPT to tidy an email. Someone else pastes a client note into a summariser. A manager tries an AI meeting tool. A team member uploads a spreadsheet to a free “AI assistant” they found online.

None of that is necessarily wrong. Public AI tools can be genuinely useful. But there is an important question many businesses skip:

Where is your data going?

For SMEs and professional businesses in Cheltenham and across Gloucestershire, this is not just a technical issue. It affects client confidentiality, supplier agreements, HR data, commercial information, regulatory responsibilities and reputation.

The aim is not to frighten people away from AI. It is to use it sensibly.

Public AI tools are useful, but not all data belongs there

Public AI tools are services you access over the internet. You type or upload information, the service processes it, and you get an answer back. Tools like ChatGPT, Claude, Gemini and many specialist AI apps fall into this broad category.

They can be excellent for low-risk work such as:

  • rewriting generic marketing copy
  • brainstorming blog titles
  • summarising publicly available research
  • creating first-draft checklists
  • explaining unfamiliar concepts
  • improving the tone of a non-sensitive email

Used well, they can save time and improve quality.

The risk comes when people start pasting in information that should not leave the business without thought. That might include client names, contracts, quotes, internal financials, employee issues, medical details, legal information, passwords, customer exports, proprietary processes or commercially sensitive sales data.

The problem is not simply “AI is unsafe”. The problem is that many businesses do not know which tools are being used, what data is going into them, what settings apply, or who has approved the process.

That is where a little structure makes a big difference.

What private or local AI means

Private AI is not one single product. It is a way of designing AI use so the business has more control over data, access and risk.

In practice, it might mean:

  • running an AI model on a local computer or private server
  • using an enterprise AI account with stronger data controls
  • connecting AI only to approved documents and systems
  • keeping sensitive data inside your own environment
  • limiting which staff can use which tools
  • logging what the AI is asked to do
  • adding human review before anything is sent to clients or published

Local AI usually means the model runs on hardware you control, such as a company machine, workstation or server. It can be slower or less polished than the biggest public tools, but it can be useful where privacy, cost control or repeatable internal workflows matter.

For many SMEs, the best answer is not “all public” or “all private”. It is a sensible mix.

A simple way to decide what goes where

A useful starting point is to divide AI tasks into three categories.

1. Safe for public tools

This is material you would not worry about being widely seen, or content that does not identify clients, staff or sensitive business details.

Examples include a generic blog outline, a public tender summary, a first draft of a customer FAQ, or ideas for improving a non-confidential process.

2. Use with care

This includes business information that may be useful to process with AI, but should be anonymised or handled in an approved tool.

Examples include sales notes with names removed, support ticket themes, internal process descriptions, or supplier comparisons.

3. Keep private

This is data that should not be pasted into random AI tools.

Examples include client files, legal documents, HR issues, financial records, passwords, health information, confidential proposals, unreleased product plans and anything covered by a specific confidentiality agreement.

Once you have those categories, staff have something practical to follow. Without them, everyone makes their own judgement in the moment.

What this looks like in a real project

In my Cheltenham Times AI agent experiment, one of the rules from the start was to keep the setup as private and secure as possible, rather than sending every small task through a random mix of online tools with no thought about data, accounts or access.

That project is a useful example because it was not just an AI writing demo. The agent helped research, organise, draft, categorise, monitor sources and support useful local tools. But it also needed rules: what counted as Cheltenham, which sources were reliable enough, when something should stay in review, and where a human needed to check the result.

The same thinking applies inside a business. The value is not “use AI everywhere”. The value is designing a workflow where AI does useful work, within sensible boundaries.

I have also experimented with AI-first business software, including CRM-style workflows where agents can help with tasks, email triage and role-specific support. That kind of system becomes much more interesting when it is connected carefully to the right data, with access controls and human oversight, rather than being treated as a chatbot bolted onto the side.

The business owner’s checklist

If your team is already using AI, start with these questions:

  • Which AI tools are staff using today?
  • What information are they allowed to paste or upload?
  • Are there any client, HR, finance or legal documents going into public tools?
  • Do paid accounts have data protection settings switched on?
  • Who approves new AI tools?
  • Are outputs checked before they go to clients, prospects or the public?
  • Could a private or local workflow handle the sensitive parts instead?
  • How will you measure whether the AI is actually saving time or improving quality?

You do not need a 40-page AI policy to begin. You do need clear rules that ordinary staff can understand.

A sensible first step

Pick one useful AI workflow and map it properly.

For example: “summarise enquiry emails and draft follow-up tasks”, “turn approved knowledge-base notes into client-facing FAQs”, or “monitor public sources for local opportunities”.

Then ask:

  • What data does this workflow need?
  • Which parts are sensitive?
  • Could anything be anonymised?
  • Should this run in a public AI tool, an approved business account, or a private/local setup?
  • Where does human approval sit?
  • What outcome will we measure?

That is a much better starting point than letting everyone experiment separately and hoping nothing awkward happens.

AI can be extremely useful for SMEs, but it should be designed around the business, not dropped in casually through whatever tool someone found that week.

If you run a business in Cheltenham or Gloucestershire and want to understand what AI could safely do in your organisation, I can help you identify practical opportunities, choose the right public/private mix, and build workflows with proper guardrails.

If that would be useful, book a short AI consultancy call or get in touch and ask: what could AI do safely in our business?

In Blog
Keep reading

Related articles

4 min read

An AI Early-Warning Radar for Retainer Client Health

Retainer clients rarely disappear overnight. More often, the warning signs arrive quietly: fewer replies, shorter emails, slower approvals, payments drifting a few days later than usual, or a…

4 min read

How AI Can Help Stop Expense Recharge Leakage

Some profit leaks are obvious. A project overruns, a client pushes back on scope, or a fee is discounted too heavily. Other leaks are quieter. One common example…

Want help putting AI to work?

If this article sparked an idea, let's have a short call about what AI could do in your business — no jargon, no obligation.