Three things have to be under your control: the data, the model, and the hardware. Most products called “private” only give you two.
Every AI setup has three parts: your data, the model that does the thinking, and the hardware it runs on. Privacy is not one switch — it is whether all three sit inside your walls.
You share the model with everyone who uses it — including your rivals. The provider sets the price, the rules and what happens to what you send.
Your files stay local. But every question still goes to a model you share with everyone else, so what it learns from you does not stay with you.
Nothing is shared. The model, the machines and the files are yours, and what the system learns stays inside the building. AIPod Mini sits here.
Public AI and API-driven AI are the mechanisms Nadella describes. Every prompt teaches the model something about your business; every correction teaches it more precisely. None of that comes back to you — it goes to whoever owns the model, and to every other company renting the same one, including your competitors and the startups entering your market. It can even reach the foundation model itself, which may end up competing with you.
This is also what makes AI different from every system before it — old IT retrieved what you gave it; it did not learn from what you asked. Two of AI’s five memory layers never reset: behavioral memory and system-level learning, corrections folded into the model itself. Neither can be undone once written, which turns a shared model into a one-way door.
A product can keep your files on your own storage, run on hardware you bought, and still send every question to a model somebody else owns and operates. That is usually sold as private AI. Please re-read Satya Nadella’s warning above.
The vector database reads files by meaning, not keyword, finding relevant pieces even when the source is unstructured and messy.
Prompts, source data, embeddings and answers never leave your environment.
Some industries cannot risk sending data out at all. Healthcare, finance, government, legal and defense run under rules written before AI could remember anything. For a regulated business, that uncertainty is itself the violation.
Directors already carry a duty to oversee where company data lives. That duty does not pause when an agent makes the decision instead of an employee — an agent can email a customer or approve a claim thousands of times a day, with no one reading most of it. Boards can be held responsible for that, the same way they are already held responsible for data stored in the wrong place.
Iterate builds private AI for hospitals, banks and other regulated organizations, and saw this gap directly. That is why it built AgentWatch: it logs every agent action, enforces policy at the gateway rather than after the fact, and gives a board a record to point to.
That said, shared models are not wrong to use — most companies land on a hybrid mix. Equinix, which operates 280+ data centers worldwide, estimates roughly 80% of workloads run better private, meaning 20% could run safely in public settings.
Read: “The Reverse Information Paradox” — Nadella (Jul 12, 2026). Also: The Oohs, Awes, and Dangers of AI Memory — the five layers in full. Also: You Cannot Govern What You Cannot See — the case for AgentWatch. Also: Most AI Is Shared, Not Private.
A joint educational series on private AI and the AIPod Mini. NetApp — the governed data-control layer. Iterate.ai — the private intelligence layer.
