A decision, not a doctrine
Own the capacity that deserves to be owned.
Private AI is compelling where the data route, operating continuity or sustained workload matters. Hosted AI remains compelling where the best model, instant scale and managed operation matter.
The strongest architecture is often private-first hybrid: keep routine and sensitive work local, with a deliberate hosted route for approved exceptions.
Operational ownership
The handover should make responsibility easier to see.
- 01 / Owner
- Name who controls updates, access, recovery and incidents.
- 02 / Record
- Make versions, tests and handover evidence visible.
- 03 / Exit
- Keep portability and supplier boundaries written down.
Control what changes
Owned capacity gives the organisation more control over the model version, access route, retention, outage behaviour and upgrade timetable.
It does not remove dependence on hardware suppliers, open-source projects, model licences or skilled operation.
Change record
A controlled change leaves an evidence trail
- Request Reason, owner and affected service.
- Test Focused acceptance and rollback plan.
- Approve Named person accepts the change.
- Record Version, date and result retained.
Look behind the claim at the operating record.
Management, recovery, evidence and physical serviceability make responsibilities easier to inspect at handover.
Make spend visible
A hardware purchase converts some recurring variable spend into a capital asset and operating costs. That can improve predictability for sustained use.
For ten light users, a hosted subscription may be dramatically cheaper. The TCO tool is designed to show “no break-even” where that is the honest result.
Recovery boundary
Recovery spans equipment, configuration and business data
- Equipment Hardware fault and warranty route.
- System Build record, settings and secrets.
- Data Backup, retention and restore authority.
- Service Fallback, incident and return to use.
Keep the frontier path
A local model need not replace every cloud model. A governed router can keep sensitive work local and send an explicitly approved task to a hosted provider.
The policy, not the marketing copy, decides which data may cross the boundary.
Exit path
Ownership should preserve a practical route out
Build evidence before confidence
The model must answer representative questions, meet a latency target and behave correctly under expected concurrency. The site conditions and support ownership must also pass.
If those tests fail, the correct answer is to change the design or not buy.
Questions answered
Straight answers to common questions
Will a private AI server always be cheaper than cloud AI?
No. SaaS is usually the better-value choice for a small team with light or irregular use. Owned capacity becomes more credible when privacy, offline operation, many shared users or sustained workloads have independent value. We show the comparison rather than forcing the server answer.
Will private AI remove vendor lock-in?
Open models and standard APIs can reduce lock-in, but hardware, runtimes, model formats, licences and operational knowledge still create dependencies.
Can private and cloud AI work together?
Yes. A private-first hybrid design can route approved workloads according to data sensitivity, quality, cost and continuity requirements.
Continue the decision
Useful next steps
Put the claim to work
Turn this guidance into a testable requirement.
The brief asks about workload and operating conditions - not just budget.