Private AI is what a UK business ends up wanting about six weeks after its first serious experiment with a chatbot. The early wins are real — faster drafting, quicker research, tidier meeting notes — and then someone asks the awkward question: where exactly did that board paper go when Dave pasted it into a free chatbot to “make it punchier”? The honest answer is that it left your estate, crossed at least one jurisdiction, and may now sit in a vendor’s logs under terms nobody in your business has read.

This guide is the general, all-sector version of the question we answered for one profession in our private AI assistant for law firms piece: how do you get the benefit of a large language model without feeding it things you are paid to protect? It covers the full private AI decision in order — what the term really means, how company data actually leaks, what UK law expects, the five deployment levels from enterprise chatbot tiers to fully self-hosted open-weight machines, realistic costs, security controls and vendor due diligence, and a 90-day rollout plan.

None of this requires a research team. Every private AI option in this article is buyable or buildable today by an ordinary UK company with an ordinary IT budget, and the cheapest credible option costs less per user than a mobile phone contract. What it does require is a deliberate choice — because the default, doing nothing while staff quietly use consumer tools, is the one option that guarantees company data is being exposed.

What Private AI Actually Means

private ai for uk businesses b house plain pitched roof

Private AI is not one product. It is a spectrum of ways to use modern language models where you control — contractually, technically, or physically — what happens to the data you put in. The phrase gets used loosely by vendors, so it pays to be precise about what you are actually buying.

The one question that defines private AI

Every private AI conversation reduces to a single question: when a member of staff submits a prompt, who can read it, store it, and learn from it? For a free consumer chatbot the answer is “the vendor, indefinitely, and possibly their next model”. For a self-hosted model on a workstation in your server room the answer is “nobody outside the building”. Everything else sits between those poles.

What private AI does not mean

Private AI does not mean secret, and it does not mean offline by definition. A business tier of a mainstream assistant, bought properly with a data processing agreement and training exclusion, is a legitimate private AI arrangement even though the prompts still travel to a vendor’s servers. Equally, running a model on your own hardware does not automatically make the surrounding system safe — a self-hosted deployment with no access control is private from the vendor and wide open to everyone on your network.

Why UK businesses are moving to private AI now

Three pressures are converging. Staff adoption is already universal — assistants are in browsers, phones and office suites whether you sanction them or not. Regulatory attention is sharpening, with the ICO publishing detailed guidance on artificial intelligence and data protection and sector regulators following. And the technology finally cooperates: open-weight models you can run on your own hardware are now genuinely good, as we showed in our open-weight AI models guide. The private AI conversation stopped being theoretical the moment a £2,000 workstation could run a model that drafts, summarises and answers questions at a professional standard.

How Company Data Leaks Into Public AI Tools

private ai for uk businesses c shredder box top slot

Before choosing a private AI level, it helps to be blunt about the leak paths. Most of them are mundane. Nobody is hacking you; your own people are uploading your data one helpful paste at a time.

Prompts and pasted documents

The dominant leak is the paste. Contracts, salary spreadsheets, customer lists, source code, board minutes — anything a person wants summarised or improved gets pasted into whatever chatbot is nearest. The industry’s canonical example remains Samsung, which restricted staff use of external chatbots in 2023 after engineers pasted confidential source code into one. The lesson was never “chatbots are dangerous”; it was that convenience beats policy every single day.

Consumer tools that learn from conversations

Free consumer tiers of the big assistants typically reserve the right to use conversations to improve their models unless the user finds and flips an opt-out. That is exactly the arrangement we examined when OpenAI updated its terms — see our analysis of ChatGPT ad personalisation and the updated privacy policy. A business cannot meet its confidentiality obligations through settings its staff configure individually on personal accounts.

Connected files, plugins and integrations

Modern assistants do not just take pastes — they connect to drives, inboxes and calendars. Each connector is a standing grant of access, made by one employee, to a corpus of company data. An assistant connected to a shared drive has effectively been handed every document on it, including the ones the employee has never opened.

Shadow AI

Shadow AI is the sum of every unsanctioned tool in use across the business: the free account on a personal email, the browser extension that “reads” every page, the meeting-notes bot a supplier invited into your call. You cannot contract, configure or monitor tools you do not know exist, which is why every serious private AI programme starts with discovery, not procurement.

Retention, logs and legal process

Even where a vendor does not train on your data, prompts commonly persist in logs for abuse monitoring, sometimes for long periods, and may be discoverable under foreign legal process depending on where they are stored. “We do not train on your data” and “we do not keep your data” are two different promises. Read for both.

private ai for uk businesses d three bollard posts row

Nothing in UK law prohibits using LLMs on company data. What the law does is attach conditions that map remarkably cleanly onto the private AI levels in the next section — which is convenient, because it means the compliant choice and the sensible engineering choice are usually the same choice.

UK GDPR applies to prompts

If a prompt or an uploaded file contains information about identifiable people — customers, employees, complainants — then processing it through an AI service is processing personal data, full stop. You need a lawful basis, you owe transparency, and the ICO’s guidance on AI and data protection expects you to have thought about accuracy, minimisation and individual rights before deployment, not after. A vendor processing prompts on your behalf is a processor, and Article 28 of UK GDPR requires a written contract — a data processing agreement, not a consumer terms-of-service page.

International transfers

Most mainstream AI services process data outside the UK. That is lawful with the right mechanism — an adequacy decision, the UK International Data Transfer Agreement, or the UK addendum to EU standard contractual clauses — but it must actually be in place, and you must know where processing happens. A private AI level that keeps inference inside a UK or EU region removes most of this workload at a stroke.

Confidentiality is broader than data protection

UK GDPR only covers personal data. Your duty of confidence to clients, your NDAs with partners, and your trade secrets protection cover everything else — pricing models, source code, unannounced plans. Pasting a partner’s confidential document into a consumer chatbot can breach a contract even where no personal data is involved. This is why private AI is a board topic, not just a DPO topic.

Sector rules stack on top

Regulated firms carry extra duties. FCA-regulated businesses must fold AI services into their operational resilience and outsourcing thinking — the FCA’s FG16/5 cloud guidance expects a data residency policy, audit rights and an exit plan for material outsourced services, and from July 2026 the largest cloud providers are formally designated as critical third parties to the UK financial system. Schools, health providers and charities have their own overlays. The pattern is constant: the more regulated you are, the higher up the private AI ladder you should start.

The scale of the underlying risk

The government’s Cyber Security Breaches Survey 2025/2026 puts numbers on the environment all this sits in: 72% of UK businesses call cyber security a high priority, 43% identified a breach or attack in the last year, only 31% assign board-level responsibility, and 44% sought external guidance. AI simply adds a new, very convenient channel to an already leaky landscape.

UK businesses and cyber risk — Cyber Security Breaches Survey 2025/2026
Rate cyber risk a high priority 72%
Sought external guidance 44%
Identified a breach or attack 43%
Board-level responsibility assigned 31%

The Private AI Deployment Ladder

private ai for uk businesses e balance scale two pans

Every option on the market fits one of five levels. Each step up buys more control and costs more effort. The private AI decision is simply choosing the lowest level that satisfies your most sensitive planned use — and being honest about what that use is.

LevelWhat it isWhere prompts goTraining on your dataTypical monthly cost
1. Consumer toolsFree/personal chatbot accountsVendor cloud, vendor termsOften yes by default£0 — and worth exactly that
2. Business tiersPaid workspace plans of mainstream assistantsVendor cloud under a DPAExcluded by default£10–£25 per user
3. API + your front endZero-retention API behind an internal appVendor API, retention limitedExcludedUsage-based, often under £200
4. Your own cloud tenantFrontier models deployed inside your Azure/AWS subscriptionYour tenant, your regionExcludedUsage plus platform overhead
5. Self-hostedOpen-weight model on your own hardwareNowhere — stays on premisesImpossible by designHardware amortisation + power

Level 1 exists only to be banned

Consumer accounts have no place processing company data. The only decision at level 1 is how you communicate the ban and what sanctioned alternative you offer, because a ban with no alternative just drives usage underground.

Levels 2 and 3 are contractual privacy

At these levels your data still travels to a vendor, and privacy rests on the contract: a DPA, a training exclusion, retention limits, and a transfer mechanism. That is genuinely fine for most day-to-day content — the contracts are real and the vendors’ enterprise reputations depend on honouring them.

Levels 4 and 5 are architectural privacy

Here the guarantee stops being a promise and becomes a network diagram. At level 4 the model runs inside your own cloud tenancy, in a region you chose, subject to your own access controls. At level 5 the weights sit on hardware you own and the data never leaves the building. These are the levels for regulated work, trade secrets and anything you would be uncomfortable explaining to a client if it leaked.

Mixing levels is the normal end state

Mature deployments are hybrids: a business-tier assistant for general drafting, a zero-retention API powering an internal tool, and a self-hosted private AI box for the genuinely sensitive workloads. The ladder is not a maturity contest — it is a routing decision per data category.

Level 2 in Practice: Business Tiers of the Big Assistants

private ai for uk businesses f fence five posts two rails

For most UK businesses the first sanctioned private AI deployment is a paid workspace tier — Microsoft 365 Copilot inside the tenant you already run, or the business plans of ChatGPT, Claude or Gemini. Bought correctly, these are respectable private AI: prompts are excluded from training by default, admin controls exist, and a genuine DPA is available.

What to checkConsumer tierBusiness/enterprise tier
Training on your promptsOften on by default, per-user opt-outExcluded by default, in writing
ContractConsumer terms of serviceDPA with Article 28 processor terms
Admin visibilityNone — accounts are personalCentral user management, audit logs
Retention controlVendor defaultConfigurable or contractual limits
Data residency optionsNoneOften UK/EU processing commitments

The Copilot arithmetic

Microsoft’s UK list pricing makes the entry point concrete: the Copilot Business add-on is £13.80 per user per month on the current promotion (list £16.10), and the bundled “with Copilot” SKUs price the capability at roughly half that uplift — Business Premium with Copilot is £24.60 against £16.90 without. For a 20-seat business, sanctioned private AI inside your existing Microsoft tenancy therefore starts at about £276 a month. We unpack whether it earns that back in our Copilot cost and ROI analysis.

What “no training” does and does not cover

The training exclusion covers model improvement. It does not automatically cover retention for abuse monitoring, human review of flagged conversations, or telemetry. It also does nothing about your own misuse — Copilot-style tools inherit the user’s existing file permissions, so years of sloppy internal sharing surface instantly in answers. Fix oversharing before rollout, not after the first awkward search result.

The residency question to ask in writing

Ask the vendor: in which countries are prompts processed and stored for our tenancy, and under which transfer mechanism? A vendor that cannot answer in one paragraph is telling you which private AI level you actually need.

Level 3 in Practice: Zero-Retention APIs Behind Your Own Front End

The step most businesses miss is that the API versions of the frontier models carry stronger data terms than the chat products built on them. API traffic from the major providers is excluded from training by default, and zero- or short-retention options exist for exactly the confidentiality reasons this article is about.

Why a thin internal wrapper changes everything

Put a simple internal web app in front of the API — one login, one system prompt, one logging policy — and you convert a hundred personal chatbot habits into one controlled private AI channel. You choose what gets logged and where, you can strip obvious identifiers before the prompt leaves, and you can switch the underlying large language model without retraining a single user. For a build like this, a few days of development work buys a level of control no off-the-shelf subscription offers.

The cost profile is absurdly good

API pricing is metered per million tokens, and a token is roughly three-quarters of a word. A team that pushes thirty million input tokens and six million output tokens a month through a mid-tier model priced at £2 per million input and £8 per million output pays £60 + £48 = £108 a month — for the whole team, not per seat. Our LLM API pricing comparison keeps the current per-model numbers; the shape of the arithmetic does not change.

Where level 3 stops

You are still sending data to a vendor, still relying on contractual retention limits, and still transferring data internationally unless you pin the endpoint to a UK or EU region. For personal data at ordinary sensitivity, well-papered level 3 is defensible. For special category data or client secrets, keep climbing.

Level 4 in Practice: Frontier Models Inside Your Own Cloud Tenant

Level 4 private AI runs the same frontier models, but the deployment lives inside your own cloud subscription — Azure OpenAI in a UK region, or Amazon Bedrock inside your AWS account. The distinction sounds subtle and is not: prompts now terminate inside infrastructure you govern, in a region you selected, under the identity, network and logging controls you already operate.

What you actually get

Your prompts are processed within your tenancy’s boundary and are not used to train the underlying models. You can put the endpoint on a private network so traffic never touches the public internet, apply your existing conditional access rules, and keep every log inside your own monitoring stack. For a regulated firm, this is usually the level where the compliance conversation goes quiet — data residency, audit rights and exit planning all reduce to cloud controls you already understand.

What it costs

Inference is metered much like level 3, with a platform premium and some fixed overhead for networking and logging. The real cost is engineering time: standing up a private AI tenant deployment properly — private endpoints, key management, quota, monitoring — is days-to-weeks of skilled work. This is the level where firms most often bring in help; our AI consulting cost guide prices what that help should cost in the UK.

The trap to avoid

A tenant deployment with the endpoint left publicly reachable and keys in a shared spreadsheet is level 4 on the invoice and level 1 in practice. The architecture only delivers privacy if the surrounding cloud hygiene — covered well by the NCSC’s cloud security collection — is real.

Level 5: Self-Hosted Private AI on Your Own Hardware

At the top of the ladder, the model itself moves in-house. Open-weight models — Llama, Mistral, Qwen, DeepSeek and a fast-improving field we track in our open-weight guide — can be downloaded and run on hardware you own. Company data processed this way never crosses your firewall. There is no vendor, no DPA, no transfer analysis, because there is no third party.

What self-hosted private AI looks like in 2026

A single workstation with a modern GPU, running an inference server such as Ollama or vLLM, serves a quantised 27–70B parameter model to a whole small business over the local network. Smaller models matter too: as our small language models guide shows, a well-chosen compact model handles summarisation, drafting and classification at a fraction of the compute. Quantisation — storing weights at lower precision — is the trick that makes this affordable: it shrinks memory needs by two-thirds or more with modest quality loss.

What you give up

Self-hosted models trail the frontier on the hardest reasoning tasks, and you inherit the operational work: updates, monitoring, capacity and backup are yours now. A sensible private AI programme sends the sensitive 20% of workloads to the box in the server room and leaves the brilliant-but-cloud-bound frontier models doing the harmless 80%.

When self-hosted private AI is the right answer

Choose this level when the data is such that no contract makes you comfortable: client-privileged material, unpublished financials, source code that is the business, M&A work, anything under an NDA that forbids subprocessors. It is also the only level where an internet outage does not take your AI capability with it.

What Private AI Costs: A Worked Example

Costs only mean anything against a scenario, so take a concrete one: a 20-person UK professional services firm that wants sanctioned AI for everyone and a genuinely private channel for sensitive work. Here is the monthly private AI arithmetic for the four buyable levels, using the figures from earlier sections.

The four private AI routes priced

Copilot Business add-on for all 20 staff: 20 × £13.80 = £276 a month. The API route behind an internal wrapper, at the usage profile above: £108 a month in metered tokens. A rented cloud GPU for a self-managed model — a mid-range card at £1.50 an hour, powered up 8 working hours a day, 22 days a month — costs 1.50 × 8 × 22 = £264 a month. And an owned workstation: a £4,500 machine written off over 36 months is £125 a month, plus roughly £30 of electricity, so about £155 a month with no per-user or per-token component at all.

RouteBasisMonthly costScales with
Business-tier seats (Copilot add-on)20 users × £13.80£276Headcount
Zero-retention API + internal app36m tokens at £2/£8 per million£108Usage
Rented cloud GPU£1.50/hr × 8h × 22 days£264Hours powered on
Owned workstation, self-hosted£4,500 over 36 months + ~£30 power£155Nothing — flat
Monthly cost of each route — 20-person worked example
Business-tier seats £276
Rented cloud GPU £264
Owned workstation £155
Zero-retention API £108

Reading the numbers honestly

Three things stand out. First, every route is cheap against one leaked client document. Second, the routes scale on different axes — seats, tokens, hours, or nothing — so the right mix depends on whether your usage is broad and shallow or narrow and heavy. Third, the owned workstation’s flat £155 makes self-hosted private AI the cheapest route at steady heavy usage, which surprises people who assumed privacy was the premium option. Hardware sizing has its own subtleties — VRAM is the binding constraint, not CPU — and one-off setup effort of a few days is not in these monthly figures.

The hidden line items

Budget for the things that are not licence fees: a day or two of policy and DPIA work, staff training (an hour, honestly), and for levels 3–5 some integration effort. If you want the whole programme handled, that is a definable project rather than an open-ended engagement — the same shape as any well-run piece of AI strategy work.

RAG: Using Your Documents Without Handing Them Over

Most business value comes not from the model’s general knowledge but from pointing it at your own documents — answering questions from your policies, contracts and project files. The standard technique is retrieval-augmented generation, and it deserves its own privacy analysis because it is where the largest volume of company data meets the model.

How RAG keeps data local

RAG converts your documents into embeddings — numerical fingerprints — stored in a vector database, retrieves only the handful of passages relevant to each question, and sends just those passages to the model alongside the prompt. Done at level 4 or 5, the whole pipeline — embedding model, vector store, retrieval — runs inside your estate, and the language model uses natural language processing over a few retrieved paragraphs rather than ingesting your archive wholesale. The model never “learns” your documents; it reads short extracts on demand and forgets them when the response is done.

The permission trap

A RAG system flattens permissions by default: index everything, and the intern’s question happily retrieves the directors’ salary file. Retrieval must be permission-aware — filter results by the asking user’s rights before the passages reach the model. This is the single most common private AI build mistake we see, and it is a rerun of the Copilot oversharing problem in home-built form. Preparing the corpus properly is its own discipline; our guide to preparing business data for AI covers the data-quality half, and our piece on training LLMs on your own data maps where RAG ends and fine-tuning begins.

Fine-tuning changes the risk class

Fine-tuning bakes your data into model weights. A fine-tuned model can regurgitate training examples, so treat the tuned weights with the same sensitivity as the data that went into them — which usually means fine-tune only at level 4 in a locked-down tenancy, or at level 5 on your own hardware, never by uploading your corpus to a convenience service.

Security Controls That Make Private AI Genuinely Private

Choosing a level is half the job. The other half is the controls around it — because the threat model for an internal AI system includes your own staff’s enthusiasm, malicious documents, and ordinary credential theft.

The baseline private AI control set

Single sign-on in front of every AI surface; role-based access to system prompts and connected corpora; TLS everywhere including on the internal network; encrypted storage for logs and the vector store; and patched, monitored hosts exactly as you would run any other server. None of this is AI-specific, which is the point — a private AI deployment is an IT system and belongs inside your existing managed IT services regime, backup, monitoring and all.

The AI-specific layer

Two references should sit on the desk of whoever builds this. The NCSC’s guidelines for secure AI system development cover the lifecycle — secure design, development, deployment and operation. The OWASP Top 10 for LLM applications catalogues the failure modes peculiar to language models, with prompt injection at number one: a malicious instruction hidden inside a document your RAG system retrieves can steer the model into revealing or exfiltrating what it can see. Treat every retrieved document as untrusted input, cap what any single session can access, and keep the model’s tool permissions minimal.

Logging without creating a new honeypot

Log private AI prompts and responses — you need this for incident response and quality — but recognise that the log is now one of the most sensitive datasets you hold, a searchable transcript of everything staff asked. Restrict access tightly, set retention deliberately, and include the log store in your breach planning. For monitoring the model side, our AI risk assessment template gives you a scoring structure that stands up to audit.

Data minimisation as a habit

The cheapest control remains sending less. Strip client names when the task is “improve this paragraph”. Use reference IDs instead of real identifiers in internal tools. Redact before you retrieve. Minimisation is also the control regulators most like to see evidenced, because it shows the thinking happened before the incident.

Governance: Policy, DPIA and Vendor Due Diligence

The paperwork layer is short but load-bearing. Three artefacts cover a UK private AI programme: an acceptable use policy, a DPIA where personal data is involved, and a due diligence record per vendor.

The acceptable use policy that people actually follow

One page beats twelve. Name the sanctioned tools, define the data categories that may and may not enter each private AI level, ban personal accounts for work data in plain words, and say what happens next when someone is unsure — a named person, not a committee. Review it quarterly, because the tool list will change.

When a private AI deployment needs a DPIA

If your deployment processes personal data in ways likely to result in high risk — profiling, large-scale processing, novel technology, which describes most serious AI rollouts — a data protection impact assessment is required, and the ICO’s controller and processor guidance shapes the vendor half of it. A DPIA for a private AI deployment is typically a day’s structured work, and it doubles as the design review that catches the permission trap early.

The eight questions that sort vendors quickly

QuestionThe answer you want
Are our prompts used to train or improve models?No, by default, stated in the contract
How long are prompts and outputs retained, and can we set it?A specific number, configurable, with a zero option
Where is processing and storage located for our account?Named regions, UK/EU available
Is a UK GDPR Article 28 DPA available?Yes, standard, with subprocessor list
Who reviews flagged conversations, and under what control?Documented process, opt-outs available
What security certifications cover this product?Independent certification, current, in scope
Can we export and delete all our data on exit?Yes, self-service, with deletion confirmation
What happens to our data if you are acquired?Contractual continuity of the same terms

The wider rulebook is converging

The UK’s pro-innovation approach keeps AI regulation principles-based for now, the EU AI Act adds staged obligations that touch UK firms selling into Europe, and frameworks such as the NIST AI Risk Management Framework and the OECD AI principles give boards a shared vocabulary. None of them forbids anything in this article; all of them reward being able to show your working — which the three artefacts above are.

A 90-Day Private AI Rollout Plan

Ninety days is enough to go from shadow AI chaos to a governed, layered deployment. The plan assumes one accountable owner with a few hours a week and a modest budget.

Days 1–30: discover and set your private AI levels

Survey what is actually in use — anonymously, or you will learn nothing. Classify your data into three or four categories with a named private AI level for each. Write the one-page acceptable use policy. Pick your level 2 product and negotiate the DPA. Quick win: turn on the training opt-outs and retention limits in whatever tools staff already use legitimately.

Days 31–60: deploy the sanctioned layer

Roll out the business tier to everyone with an hour of training built around your own examples. Stand up the level 3 wrapper if you have internal development capacity, or scope it as a small project if not. Run the DPIA for any workload touching personal data. Start the leavers-and-joiners process for AI accounts — the forgotten offboarding path is a slow leak.

Days 61–90: build the private lane

Pilot the private AI lane at level 4 or 5 with one team and one real use case — contract review, board pack summarisation, whatever hurts most today. Wire the logs into your monitoring. Test the permission-aware retrieval with a hostile eye. Then write the two-paragraph internal announcement that tells everyone what goes where, and retire the excuses.

What good looks like at day 90

Every member of staff has a sanctioned assistant. Sensitive data has a private AI lane that never leaves your control. Three governance artefacts exist and are dated. And the next board meeting gets a one-slide answer to “what is our AI exposure?” — which, statistically, puts you ahead of the 69% of UK businesses that assign no board-level responsibility for cyber risk at all.

The Bottom Line for UK Businesses

Private AI is not a product you buy once; it is a routing policy for your company’s information, enforced by contracts at the bottom of the ladder and by architecture at the top. The move that matters is the first one: decide deliberately, this quarter, which data goes to which level — because your staff decided informally months ago, and their default setting is convenience.

The encouraging news is how affordable deliberate has become. £276 a month puts a governed assistant in front of twenty people. £155 a month runs a capable model that never sends a byte off-site. A day of policy work covers the governance. Against the cost of one confidentiality breach — commercial, regulatory or reputational — private AI is one of the cheapest risk reductions available to a UK business in 2026. If you want a partner for the design and build rather than a DIY quarter, that is exactly the shaped, fixed-scope engagement a good consultancy should offer.

References