Private AI for business: three ways to get it and what each protects

Private AI is AI that runs on your company’s data without that data training someone else’s model or leaving your control. Where your records are stored and where a model processes them are separate questions, and you need a written answer to each. If you run a smaller manufacturer or distributor, you can get private AI in three ways: a business plan of a public assistant such as ChatGPT or Copilot, a private deployment on a cloud account you control, or a model on your own server. This guide sets out what each one protects and what it leaves open, and ends with a checklist for any vendor.

A machine control panel with a touchscreen, a keyed emergency stop and a yellow hose reel in front

What private AI means for a business

For a business, private AI is an AI system that reads your quotes, drawings, orders and email while your company keeps control of that data. Four terms decide how private a setup is:

Private AI for a business does not need to retrain a model on your files. It can use retrieval: the system finds the records that answer a question and hands them to the model with the question. AWS describes this method, retrieval-augmented generation (RAG), as working “all without the need to retrain the model.”

In Statistics Canada’s survey for the second quarter of 2026, 19.2% of businesses used AI to produce goods or deliver services. Among businesses with 20 to 99 employees, 22.3% named cybersecurity or privacy concerns as a barrier, and at 100 employees or more, 30.0% did.

Two questions decide whether a setup is private

The Canadian Centre for Cyber Security’s generative AI guidance tells users to “Avoid providing PII or sensitive corporate data as part of the queries or prompts.” PII is personally identifiable information. When you do want AI to read that kind of data, two questions test the setup.

The first is where your records sit when nobody is using them: which company holds them, in which country, and who can open them. The second is what happens to a prompt after the answer comes back: where the model ran, whether a copy was kept and for how long, and whether the copy can be used for training. A vendor that answers the first question with “hosted in Canada” may still send every prompt to a model in the United States.

Business plans of public assistants: a private ChatGPT for your team

The quickest route is a business plan of an assistant your staff may already use. ChatGPT Business, Claude Team, Microsoft 365 Copilot Business and Gemini in Google Workspace put staff on company accounts, and each vendor says it does not train on business content by default. Google’s Workspace privacy hub, for example, says Workspace does not use customer data for training “without customer’s prior permission or instruction.”

PlanWhat the vendor says about trainingHow it charges, checked September 27, 2026
ChatGPT BusinessNot used for training or improving models by default (OpenAI)Per user per month, billed monthly or annually, with at least two paid seats (OpenAI)
Claude TeamModel training “None by default” (Anthropic)For teams of 2 to 150. A standard seat is charged per member per month, billed annually or monthly (Anthropic). Viewed from Canada, the pricing page showed its prices without naming the currency (Anthropic)
Microsoft 365 Copilot BusinessPrompts, responses and the email, chats and documents Copilot reads through Microsoft Graph are not used to train the large language models behind Copilot (Microsoft)Per user per month, paid yearly. It is an add-on to an eligible Microsoft 365 Business plan (Microsoft)

Personal accounts follow other rules. OpenAI says of its services for individuals, “we may use your content to train our models,” with an opt-out, and Claude’s pricing page lists training as “Opt-out” on its personal plans. A business plan moves staff off those accounts, and Shadow AI covers finding the ones already in use.

What a business plan protects

Training is off by default, and staff work in accounts the company controls and can close. Microsoft adds that Copilot “only surfaces organizational data to which individual users have at least view permissions,” so it follows the file permissions you already have.

What a business plan does not protect

Vendor-by-vendor detail is in ChatGPT alternatives for business in Canada, and the settings to switch on or off in each tool are in secure AI at work.

A private deployment on a cloud you control: a private LLM

A large language model (LLM) is the kind of model behind ChatGPT, Claude and Copilot. A private LLM deployment means your company, or a vendor working in your name, opens an account with a cloud provider such as Amazon Bedrock, Microsoft Foundry on Azure, the OpenAI API or the Anthropic API. Your own application sends requests to the model through an API, a connection one program uses to call another, and your account settings decide what the provider keeps.

The providers say they do not train on this traffic: AWS for Bedrock, Microsoft for Azure, where prompts are also “NOT available to OpenAI,” OpenAI for its API unless you opt in, and Anthropic for its API by default. What each request costs is covered in Claude API pricing.

What a private deployment protects

The main gain is a retention setting you can write down and check. Amazon Bedrock has a data retention mode, set per account or project in each region. In the mode called “none,” “No request or response data is written to durable storage by AWS or shared with the model provider.” If you then call a model that requires retention, “Amazon Bedrock will block the request and return an error,” so a model that keeps copies cannot be used by mistake. New accounts start at “inherit,” which falls back to each model’s own default, so the mode has to be set on purpose. A service control policy, an AWS rule an organization applies to its member accounts, can stop anyone in those accounts from changing it. It does not cover the organization’s management account.

OpenAI and Anthropic offer zero data retention on their APIs by agreement. OpenAI’s is “subject to prior approval by OpenAI,” and without it, OpenAI keeps API abuse monitoring logs for up to 30 days. Anthropic’s is “subject to Anthropic’s approval,” and requests are “reviewed and applied on a per-organization basis.” Under it, Anthropic still keeps its safety classifier results and may store data where it needs to comply with the law or combat misuse.

What a private deployment does not protect

A model on your own server: private GPT and self-hosted AI

The third way removes the model provider. You run an open-weight model, meaning one whose weights (the numbers the model learned in training) are published so anyone can download and run it, on a server that you or your vendor operate. The server needs a GPU, the graphics chip that does the model’s arithmetic.

OpenAI’s gpt-oss models are one example, released under the Apache 2.0 licence. OpenAI says gpt-oss-120b “achieves near-parity with OpenAI o4-mini on core reasoning benchmarks” while running on a single 80 GB GPU, and that gpt-oss-20b “can run on edge devices with just 16 GB of memory.” The name “private GPT” is also used by PrivateGPT, an open-source project that describes itself as an “API layer for private AI applications on local models.”

The server can sit in your building or in a data centre. DigitalOcean, for example, lists an NVIDIA H100 GPU with 80 GB of memory and an RTX 4000 Ada with 20 GB, each charged per GPU per hour on demand, and its availability table shows both in its Toronto region. DigitalOcean bills in US dollars. A GPU left on all month is billed for every hour, about 730 of them. DigitalOcean bills a GPU Droplet until it is destroyed, even when it is powered off. Cohere sells private deployments in which prompts, outputs and fine-tuned models (copies of a model further trained on your own data) “stay entirely within your environment,” in a virtual private cloud (a walled-off section of a cloud account) you manage or on premises, including air-gapped setups with no outside network connection. Running a model on your own hardware is covered in more depth in local LLM.

What your own server protects

When the server sends nothing out, the prompt and the answer never leave the machine, so no provider’s retention rule applies to them. The model reads your records on the same server that stores them, and no zero data retention agreement is needed because no outside provider sees the request.

What your own server does not protect

The three ways to get private AI, side by side

The table sums up the sections above. The vendors’ pages were checked on September 27, 2026, and these settings change often.

WayTrains on your dataWhere records are storedWhere prompts are processedWho runs itWhat it takes to staff
Business plan of a public assistantNot by default, though feedback can be keptWith the provider, in Canada on some plansMay be outside CanadaThe providerAn account administrator
Private deployment on a cloud you controlNo, per AWS, Microsoft, OpenAI and AnthropicThe region you choose, including Canada on AWSDepends on the model and regionYour team or vendor, in your accountAn application builder and a written retention setting
Model on your own serverNo outside provider sees the dataOn your serverOn the same serverYou or your vendorSomeone for patching, backups, restores and capacity

The ways also combine. Records can live on a server you control while a hosted model reads them under a written retention setting, and you can change the model later without moving the records.

Which way fits your records

Tell Derik which systems hold your records and which of them must stay in Canada. He will tell you which of the three ways fits and what it takes to run.

Start a conversation

What Canadian law asks when AI reads personal information

Customer contacts and employee time records often contain personal information. Under clause 4.1.3 of PIPEDA, the federal privacy law for businesses, an organization “is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing.” It must use “contractual or other means to provide a comparable level of protection.”

The Privacy Commissioner of Canada’s guidelines for processing across borders add two points. What an organization cannot do through a contract “is to override the laws of a foreign jurisdiction.” It must also tell customers that while their information is in another jurisdiction, it “may be accessed by the courts, law enforcement and national security authorities.”

Quebec asks for more. Section 17 of its private-sector privacy act says: “Before communicating personal information outside Québec, a person carrying on an enterprise must conduct a privacy impact assessment.” A privacy impact assessment is a written review of the risks to personal information. The transfer also needs a written agreement, and the same rule applies when an enterprise entrusts someone outside Quebec with keeping the information. The rule has applied since September 2023, according to the Commission d’accès à l’information. Section 3.3 requires an assessment for “any project to acquire, develop or overhaul an information system” involving personal information. In our reading, an AI system that reads personal information is such a project.

If your company is registered in the Controlled Goods Program, the program’s cloud guidance says registrants “should take note of any data residency options to ensure that their controlled goods data is stored on servers located in Canada.” That guidance speaks to storage, so ask your vendor about processing as a separate question.

Your counsel draws the conclusion for any particular deployment, and this guide is not legal advice. The wider legal picture for AI is in AI governance, and the rules for staff are in the AI policy template.

A private AI checklist for any vendor

Take these questions to any AI vendor, including ThriveAI. Each one should get a written answer. For the account settings inside each tool, use the checklist in secure AI at work, and for the wider security picture, see AI security.

Before you sign

  1. Where is our data stored at rest? Ask for the provider, the region and the country.
  2. Where does the model process our prompts? Ask for this as a separate written answer, because the region that stores data may not be the region that runs the model.
  3. Which retention mode applies, and to which model? Ask for the model and its retention setting by name, because some models require retention.
  4. Who holds the credentials? The accounts and keys the system uses should sit in your company’s directory, so you can switch them off.

In the contract

  1. No training or fine-tuning on your data without your written consent.
  2. Destruction of your data on request, with a deadline for confirming it.
  3. A named person at your company approves every write-back, meaning any email sent, record changed or order created by the system. Human in the loop explains how that approval step works.
  4. The retention mode and the model it applies to, written into the agreement, with notice before either one changes.
A phrase to question

A vendor can store your files in a Canadian data centre and still send each prompt to a model in the United States. AWS documents that pattern for its Canada (Central) Region. When a vendor says “hosted in Canada,” ask which step is hosted there: storage, processing or both.

How ThriveAI builds private AI

ThriveAI is an AI engineering company in Ottawa. It builds private AI systems on the client’s own data, for manufacturers and distributors in Ontario and Quebec. Derik Lawlis, the founder, leads every project and stays close to the build.

The platform is designed to keep each client’s data on its own server in Canada. You choose the model that reads it: one that runs on that server, or a hosted model under a written zero data retention agreement. A hosted model may process requests outside Canada, so the contract names the model and its retention setting. A named person at your company approves every action before anything is sent or saved.

Working sessions run on site with your team, in French or English. ThriveAI also runs hands-on AI training on your own documents. For what AI does inside a plant, see AI for manufacturing. For how a full platform compares with a single tool, see enterprise AI platform, and for the company, About ThriveAI.

Questions people ask

What is private AI?
Private AI is AI that runs on your company's data without that data training someone else's model or leaving your control. For a business, it comes down to two questions: where your records are stored, and what happens to a prompt after the answer comes back, including where the model ran and whether a copy was kept. Each way of getting private AI answers them differently.
Is ChatGPT Business a private ChatGPT?
Partly. OpenAI says it does not use ChatGPT Business data for training by default, and staff work in company accounts. OpenAI offers storage at rest in a chosen country, such as Canada, to eligible API customers and new ChatGPT Enterprise and Edu customers. Its inference residency covers Europe, the United States and the United Arab Emirates, so the model may process your prompts outside Canada.
What is a private LLM?
A private LLM is a large language model your company uses under its own account and settings, either through a cloud provider such as Amazon Bedrock or Azure, or on a server you control. AWS, Microsoft, OpenAI and Anthropic say they do not train on that API traffic by default. On Bedrock, a retention mode called none keeps no copy of requests and blocks any model that needs one. The model may still process requests outside Canada, depending on the model and region.
Can I run a private GPT on my own server?
Yes. Open-weight models such as OpenAI's gpt-oss can be downloaded and run on your own hardware. OpenAI says gpt-oss-120b runs on a single 80 GB GPU and gpt-oss-20b on devices with 16 GB of memory. The prompt stays on the machine, and you or your vendor take on patching, backups and restores.
Does private AI keep my data in Canada?
It depends on the setup and on the step. AWS can keep Bedrock data at rest in its Canada (Central) Region, and OpenAI can store data at rest in Canada for eligible customers. Processing is a separate question. On September 27, 2026, the Claude models checked on Bedrock's Canadian regions routed through US or global profiles, and OpenAI's Canada API region stored data without processing it there. Microsoft expects Copilot processing in Canada in 2027. On Azure, a deployment not labelled Global or DataZone processes prompts in the geography you choose, so check which models your Canadian region offers that way. A model on a server in Canada keeps both storage and processing there.
Is private AI the same as data privacy?
The two overlap. Data privacy is the set of legal duties for handling personal information, such as PIPEDA and Quebec's private-sector privacy act. Private AI is a way of setting up AI so your company's data stays under your control. The setup decides where personal information goes, and the law decides what you must do before it goes there, such as the privacy impact assessment Quebec requires before personal information leaves the province.

Contact

Use AI on your company records and keep control of them

Tell Derik which AI tools your team uses and which records you want them to read. He will tell you where each tool keeps those records and which of the three ways fits.

Prefer to talk? Book a meeting.

Your message goes to Derik Lawlis, the founder.