Your data stays home
When legal says the data can't leave, the AI project gets shelved. But where AI runs and what data it touches is designed. That restriction is the specification, not the verdict.
El YuntComunicaciones
Almost every company with sensitive data hits the same wall. Operations shows up excited, the use case is real, and someone from legal, security or compliance says the sentence that ends the meeting: our data cannot leave this place. The project is shelved "until the technology matures".
They are right about the data. They are wrong about the conclusion. A true sentence, "the data can't leave", got another one attached to it that isn't true: "so we can't use AI". Where AI runs and what information it touches is something you design; it does not come factory-set.
The fear has a basis. According to Deloitte, privacy is the most-cited concern about generative AI: close to two in five leaders ranked it first in 2025, almost double the share in 2023. Caution is fine. The mistake is using it to stop, when it is really a design requirement.
Where the idea that using AI means sending data away comes from
The first AI almost everyone used was a public chat in a browser, a service in someone else's cloud. For millions of people, "using AI" meant pasting company information into an outside system, and that experience taught a generation of managers that AI and data leaks were the same thing.
It isn't paranoia: people really do paste contracts and spreadsheets into public tools, and your security team knows it. But that describes how people reached the model, through the front door on the street, and not where AI has to run. Confusing the door with the building is the whole mistake.
Where it can run
Wherever your data is allowed to be. Location is a dial you turn according to your data policy, and the market today offers the full range:
In a provider's cloud, managed by them. The fastest option, for data that is not sensitive.
In a private cloud, under your rules, operated by someone else.
Hybrid: the sensitive part inside, the rest in the cloud.
Inside your own infrastructure, for regulated industries.
Isolated, with no external connection, for the most delicate work.
The point on that range is decided by your security, regulatory and operational requirements, not by whatever came installed.
Running inside isn't running with less intelligence
That is the second false idea, hidden inside the first. You don't have to choose between capability and control, because the work can be split by how sensitive each step is. The confidential part is processed by a local or smaller model, inside your perimeter. The heavy reasoning is done by a frontier model on non-sensitive information, or by one hosted in your own private cloud.
Some companies use enterprise versions of the major models under contracts they already have, others keep the most delicate material in their own models, and many combine both. The goal is the same: confidential information does not leave the boundary you approved, and people still get the intelligence they need.
Nor is this a new governance problem. You already trust sensitive data to cloud email and to your ERP, because you built identities, permissions, monitoring and retention around them. AI deserves that discipline and a bit more, because it acts on its own: which models are approved, which actions it can take, what gets recorded and who reviews. The idea that AI running inside is second-rate comes from the era of weak local models, and it no longer holds.
What actually makes a deployment secure
Location matters, but it is not enough. What protects the data is the controls, built into the system and not promised in a slide deck:
Identity and access: only the right people touch the system.
Isolation: one client's or one area's information does not mix with another's.
Credentials encrypted at rest and in transit, used only for approved actions.
Working documents kept in defined repositories, not drifting through shared services.
All of it built to a recognized standard, so it can be demonstrated to an auditor instead of asserted. In Chile, the bar is Law 21.719 on personal data protection. That way the question "where does our data go?" has an answer your head of security and your lawyer can verify.
At Yunt we handle it like this: each client has its own isolated instance, its data does not train models, and the operation is consistent with Law 21.719. And the digital collaborator starts under the rules of a new person: it sees what its role needs, acts through a closed list of tools, and every action is recorded with its reason, for anyone who wants to audit it.
The restriction is the specification
The next time the conversation stalls on "our data can't leave", take it as the specification and not the verdict: it tells you which deployment to choose and which steps to keep inside.
The companies pulling ahead in banking, insurance and healthcare did not wait for regulation to loosen. They put AI where their data already lived, designed so that sensitive material would not cross their perimeter, and got started while the competition was shelving the idea. If your data has to stay home, good. That is the requirement you design around.
Sources
Deloitte, State of Generative AI in the Enterprise (2025).


