All notes

When Client Data Has to Stay Local

Originally published on LinkedIn

How are NDA-bound companies supposed to survive the AI era?

There's a whole layer of companies that legally can't feed their data into any AI tool: banks, law firms, insurers, clinics, accounting firms, anyone holding client information under NDA. Every tool the rest of us rave about is off limits for them, because using it means sending confidential data to someone else's servers. So they watch the boom from outside, while the archive of everything they know about their clients sits there untouched.

We had 100,000+ documents in exactly that state.

The answer turned out to be simple: don't send them anywhere. A local model, running on our own hardware, went through the whole archive in about 24 hours. Nothing left the building, so there was nothing to disclose to anyone.

That archive now feeds a long list of automations that were impossible a year ago.

The thing I keep coming back to: the constraint was never AI capability, it was where the data goes. Local models quietly got good enough that the tradeoff mostly disappeared, and most regulated companies still plan around a choice they no longer have to make.

If your data can't leave, you're not locked out anymore.

Back to writing