Technology choices · August 2026 · 5 min read

Private AI in regulated operations

For operations governed by regulation and confidentiality, where AI runs matters as much as how well it performs. Private does not mean isolated, and control does not mean building everything yourself.

For most businesses, where an AI model runs is a detail. For operations governed by regulation, confidentiality or safety cases, it is a gating question. Asset data, incident records, compliance narratives and hard-won process knowledge cannot simply be posted to whichever service is cleverest this quarter. So the conversation turns to private AI, and immediately collects two misunderstandings.

Private does not mean isolated

The first misunderstanding is that going private means going without. The open-weight model ecosystem has matured to the point where serious capability can run inside your own environment, on your own terms, under your own governance. Retrieval over your documents, drafting against your standards, structured analysis of your data: for tasks like these, a well-deployed private model is not a compromise. It is simply the version of the capability your constraints permit, and its behaviour is easier to evaluate precisely because you control the whole stack.

Control does not mean building everything

The second misunderstanding runs the other way: that a private posture obliges you to build and host everything yourself, forever. In practice the sensible architectures are mixed. Sensitive workloads stay inside the boundary; commodity workloads without confidential content can use frontier services where their capability genuinely matters; and the routing between the two is an explicit, auditable design decision rather than a habit. The governance question is not which vendor to trust. It is which data crosses which boundary, for which task, under whose authority.

The use case decides

There is no universally correct stack, and any adviser who arrives with one is selling inventory. The honest sequence runs the other way: start from the operational task, its data sensitivity, its accuracy requirements and its failure costs, and let those choose the architecture. Sometimes that lands on a local model beside the data historian. Sometimes it lands on a carefully scoped frontier service. Usually it lands on both, with clear seams.

Regulated operations have spent decades learning to justify their engineering decisions to inspectors, insurers and their own consciences. AI does not exempt anyone from that discipline. Done properly, it extends it, and the organisations that treat it that way will adopt AI faster than the ones that treat governance as an obstacle to route around.

Written by Anthony Smith, Chief Technology Officer, Ballista.

Talking beats reading.

If your governance rules out the default AI answer, tell us what the constraint actually is. The architecture follows from there.

Your message goes to the people who would do the work.