Do local AI models protect your company's data and know-how?
Local AI models protect documents, not know-how. How data, knowledge and capability sovereignty differ, and what keeps each one inside the company.
Last updated
TL;DR Local AI models solve data sovereignty: documents never leave hardware the company controls. They do little for knowledge sovereignty, the proprietary facts and heuristics, or capability sovereignty, how the company does what it does uniquely well, because both leak through the context and workflow handed to any agent. Architecture protects those layers, not hosting location.
Data sovereignty is only the first of three things a company has to protect when it adopts AI. Data sovereignty: don't take our documents. Knowledge sovereignty: don't learn our proprietary facts, heuristics and experience. Capability sovereignty: don't learn how to reproduce what we are uniquely good at. The third becomes more important as agents move from answering questions to observing and executing entire business processes.
What are data, knowledge and capability sovereignty?
Data, knowledge and capability sovereignty are three layers of control a company keeps over what AI vendors can take. Data sovereignty covers documents and records. Knowledge sovereignty covers proprietary facts, heuristics and lessons from experience. Capability sovereignty covers the process and judgment that let the company produce results competitors cannot easily reproduce.
| Layer | What it protects | How it leaks | What protects it |
|---|---|---|---|
| Data sovereignty | Documents, records, customer data | Uploads to tools with training or long retention; data stored under a foreign jurisdiction | Contract terms, zero data retention, local models, data residency |
| Knowledge sovereignty | Proprietary facts, heuristics, pricing logic, lessons learned | Prompts, retrieval context and fine-tuning sets handed to a vendor | Sending only the context each task needs; keeping the knowledge base company-owned |
| Capability sovereignty | How the company turns information into decisions and outcomes | Agent platforms that store the workflow, the decisions and the corrections | A company-owned Map of Work and orchestration the company runs itself |
The layers nest. A company can hold perfect data sovereignty, with every document on its own servers, and still give away its knowledge in prompts. It can guard its prompts and still give away its capability if a vendor's agent platform records every step of how the work gets done.
Why do agents make capability sovereignty the hardest layer?
Agents make capability sovereignty the hardest layer because an agent that executes a business process sees far more than a chat assistant answering one question. It sees the goal, the inputs, every decision, each human correction, the exceptions and the outcome. Recorded over months, that trace describes how the company creates value.
The data layer already leaks in practice. In the Cisco 2024 Data Privacy Benchmark Study of 2,600 privacy and security professionals across 12 geographies, 48% admitted entering non-public company information into generative AI tools, and 27% said their organization had banned such tools at least temporarily. After engineers pasted sensitive internal data into ChatGPT in April 2023, Samsung restricted generative AI on company devices from May 1, 2023 (TechCrunch).
Those incidents involved documents and code. An agent leaks something subtler: the sequence of judgment calls that no single document contains. The Map of Work guide describes that trace in detail and why it is worth owning.
What do AI vendors' data terms actually promise?
Major AI vendors' business terms promise not to train on customer data by default. OpenAI says data sent to its API has not been used for training since March 1, 2023, unless the customer opts in. Anthropic says it does not train on inputs or outputs from its commercial products by default. Retention and residency are negotiated separately.
OpenAI keeps API abuse monitoring logs for up to 30 days by default, and offers Zero Data Retention only to eligible customers with prior approval. Anthropic's policy separates commercial products from consumer plans, which have their own settings. Staff using personal consumer accounts for work fall outside the business terms entirely.
Terms about training answer the data question. They do not decide where the company's workflow lives. Data held by a US-based provider can also be reached by US legal process wherever it is stored: the CLOUD Act of 2018 addresses exactly that case. For regulated or contractually restricted data, jurisdiction can matter as much as training.
When do local AI models make sense?
Local AI models make sense when data cannot legally or contractually leave the company, when a task is narrow and high-volume, or when the company wants custody of every input and output. Open-weight models such as OpenAI's gpt-oss, Meta's Llama, Mistral and Qwen run on hardware the company controls, through runtimes like Ollama, vLLM or llama.cpp.
The hardware bar has dropped. OpenAI's gpt-oss-120b, released under the Apache 2.0 license, has 117 billion parameters with 5.1 billion active per token, and runs on a single 80GB GPU such as an NVIDIA H100 or AMD MI300X. Its smaller sibling, gpt-oss-20b, has 21 billion parameters. Classification, extraction, summarization and first drafts are well within reach of models this size.
What do local models cost that cloud APIs do not?
Local models cost the company the work a cloud vendor otherwise absorbs: buying or renting GPUs, serving and scaling the model, patching the stack, securing access, and evaluating quality after every model upgrade. They also cost capability, because the frontier models from OpenAI, Anthropic and Google usually still lead on the hardest reasoning tasks.
Running a model locally makes the company its own AI vendor. Someone has to own uptime, access control, logging and the evaluation set that shows whether a new model version is better or worse on the company's own work. For a firm without an engineering team, that operational load can cost more than the confidentiality it buys. The honest comparison is local custody against a frontier API under a no-training, limited-retention contract, not local against "sending everything to the cloud."
Why don't local models protect knowledge and capability?
Local models do not protect knowledge and capability because those layers leak through the context and workflow given to an agent, not through the model's location. If prompts, agent instructions, routing rules and decision records live inside a vendor's agent platform, that platform holds the company's process, whichever model runs underneath.
The reverse is also true. A company can use a frontier API safely for capability sovereignty if its own system orchestrates the work and sends each call a single operation: extract these fields, classify this ticket, summarize this thread. No single call reveals the whole process. Hosting location decides who has custody of data. Ownership of the orchestration decides who learns the capability.
How do you protect capability sovereignty in practice?
Protect capability sovereignty by keeping three things company-owned: the Map of Work that records processes, rules, heuristics and decisions; the orchestration that sequences each task; and the evaluation data that proves quality. Then route each single operation to a model by sensitivity, with local models or private logic for steps that reveal how the company decides.
- Store prompts, agent instructions and routing rules in the company's own repository, versioned like code.
- Send each model call only the context that one operation needs, never the full methodology.
- Keep decision records and outcomes in the company's database, not only in a vendor's logs.
- Use open interfaces such as Anthropic's Model Context Protocol so the context layer is not tied to one model vendor.
- Put business accounts under no-training and, where available, zero-retention terms, and block personal consumer accounts for work.
What should an owner ask before choosing an AI setup?
An owner should ask where the workflow will live before asking which model to use. The questions that matter: does the vendor train on our data by default, how long is it retained, can we get zero retention, where is it stored, can we export our prompts and agent logic, and which subprocessors see it?
Trade-secret status adds a legal reason to ask. Under the Defend Trade Secrets Act, information qualifies as a trade secret only if its owner "has taken reasonable measures to keep such information secret." How the company handles proprietary know-how in AI tools may become part of that question, so counsel should review the setup alongside the technical choices. The NIST AI Risk Management Framework offers a neutral structure for documenting those decisions.
Choosing between local models, a frontier API or an agent platform? Get a Second Opinion before the contract is signed: a fixed-fee, two-week review of that one decision, with a written verdict and a call where I defend it.
Key takeaways
- Data sovereignty protects documents; knowledge sovereignty protects facts and heuristics; capability sovereignty protects how the company does what it does best.
- Local open-weight models such as gpt-oss-120b solve data sovereignty but add hardware, operations and evaluation work the company must own.
- OpenAI and Anthropic do not train on business API data by default, so training is rarely the main risk for commercial customers.
- Knowledge and capability leak through the context and workflow an agent receives, whichever model runs it and wherever it is hosted.
- Protect the upper layers with a company-owned Map of Work, in-house orchestration, and single operations routed to models by sensitivity.
Frequently asked questions
- What is the difference between data sovereignty and capability sovereignty?
- Data sovereignty means an AI vendor does not take or keep the company's documents. Capability sovereignty means no vendor learns how to reproduce what the company is uniquely good at: its process, judgment and decision patterns. Local models can deliver the first. The second depends on who owns the workflow and orchestration.
- Do OpenAI and Anthropic train on business data sent through their APIs?
- Not by default. OpenAI says API data has not been used to train its models since March 1, 2023, unless a customer opts in, and it keeps abuse monitoring logs for up to 30 days. Anthropic says it does not use inputs or outputs from its commercial products for training by default.
- Are local AI models good enough for business work?
- For narrow tasks such as classification, extraction, summarization and drafting, current open-weight models often are. OpenAI's gpt-oss-120b, released under Apache 2.0, runs on a single 80GB GPU. For the hardest reasoning, frontier models usually still lead, so many companies route work by sensitivity and difficulty.
- Does running a local model protect trade secrets?
- It helps with custody, which supports the reasonable measures that the Defend Trade Secrets Act requires owners to take to keep information secret. It does not stop know-how leaking through an agent platform that stores the workflow. Ask counsel how your AI setup affects trade-secret status.
- Where should a company start protecting capability sovereignty?
- Start by writing down who holds the workflow today: prompts, agent instructions, routing logic and decision records. Move that into a company-owned Map of Work and in-house orchestration, then send each model only the single operation it needs. Model choice comes after that, not before.
About the author
Disclosure
Disclosure: Giacomo Balli provides independent advisory services, including the fixed-fee Second Opinion linked on this page. He does not resell AI tools, hardware or development work, take equity, or earn vendor commissions. Company and model names are examples, not endorsements. Vendor terms change; check the current policy pages linked here before relying on them.