Local AI:what really stays in-houseand what does not
Local AI can mean two things: the model runs on your own hardware, or your system and data stay with you while the computing power comes from the cloud. Here is how the two differ, what each delivers and what the GDPR has to say.
Get in touch- What does local AI actually mean?
- How do you run an AI model entirely on your own server?
- How does local AI compare with cloud models?
- How does AI on your own server work with a cloud model?
- Which kind of local AI suits which need?
- Is local AI automatically GDPR-compliant?
- How do you choose between local AI and a cloud model?
- How do we bring local AI into your business?
- Frequently asked questions
- How to find the right route to local AI
- Where the information on this page comes from

Let's talk about your project.
First we check whether the project fits your business model. Then you get a proposal with phases and effort.
Discuss local AI or call: +49 151 1576 5566Local AI means running your AI application so that control over data and systems stays inside your company rather than being handed entirely to a cloud service. In practice, the label covers two very different set-ups. In the first, the language model itself runs entirely on your server and no text leaves your network. In the second, the application, your files and your documents sit with you, while the model that writes the answers is called as a service from an AI provider. Both have their place. Which one fits depends on the data you handle, the quality you need and who will look after the technology.
- “Local” is not one thing: either the model runs in-house, or only the system and data do.
- Open-weight models can run on your own hardware but are usually smaller than the strongest cloud models.
- German data protection authorities consider technically closed systems preferable; cloud services generally require a data processing agreement.
- Even fully local AI is not automatically GDPR-compliant: a legal basis, a risk assessment and data subject rights still apply.
On this page
- What does local AI actually mean?
- How do you run an AI model entirely on your own server?
- How does local AI compare with cloud models?
- How does AI on your own server work with a cloud model?
- Which kind of local AI suits which need?
- Is local AI automatically GDPR-compliant?
- How do you choose between local AI and a cloud model?
- How do we bring local AI into your business?
- Frequently asked questions
- How to find the right route to local AI
- Where the information on this page comes from
What does local AI actually mean?
Local AI means that you decide where your data lives and who can access it. In conversations with vendors, however, the term is used for two different things, and confusing them leads to the wrong expectations.
Option A: the model runs entirely on your premises. You download an open-weight language model and run it on your own hardware, in your own data centre or with a hosting partner of your choice. Prompts, documents and answers never leave that environment. This is also called on-premise AI or AI without the cloud.
Option B: system and data stay with you, the computing power comes from the cloud. The application, your files, knowledge base and logs sit on your server. For the actual language processing, a powerful model from a provider is called through its interface. Only the text snippets needed for each task go to the provider; the data store itself stays with you.
Both can fairly be called “local”, but only option A keeps the promise that nothing leaves the building. So when a vendor talks about local AI, your first question should be: where does the model run?
How do you run an AI model entirely on your own server?
You need a so-called open-weight model, one whose weights are published and which you are allowed to run on your own hardware. The choice has grown considerably. On 5 August 2025, OpenAI released two open-weight models, gpt-oss-120b and gpt-oss-20b, under the Apache 2.0 licence; according to TechCrunch, they are the company’s first open language models since GPT-2. Open-weight models are also available from DeepSeek and from Alibaba with its Qwen series, among others.
Hardware requirements depend on model size. OpenAI states that the larger model fits on a single data-centre GPU with 80 GB of memory, while the smaller one runs within 16 GB of memory. That puts the smaller model within reach of a well-equipped workstation; the larger one needs server hardware. If a whole team uses the model at the same time, you need extra headroom for parallel requests.
MIT Technology Review points out that organisations such as hospitals, law firms and governments may need models they can run locally for data security reasons. The benefit is clear: prompts never leave your network, no external provider processes your data, and you are not dependent on the pricing or product decisions of a cloud service.
of memory is enough for the smaller of OpenAI’s open-weight models, gpt-oss-20b, according to OpenAI.
How does local AI compare with cloud models?
Models you run yourself are usually smaller than the large models providers offer through their cloud, and that has consequences. In its gpt-oss model card, OpenAI itself notes that smaller models have less world knowledge than larger frontier models and tend to hallucinate more. On two in-house knowledge tests, both open models scored below o4-mini, a model OpenAI offers through its cloud.
For many everyday tasks that is not a problem. Summarising text, pre-sorting emails, searching internal documents or processing forms works well with smaller models, especially when the answer draws on your own documents rather than general knowledge. Demanding work such as longer analyses, multi-step processes or high-quality writing in several languages benefits noticeably from the largest models.
Then there is the effort. A local model is an application someone has to run: buying and monitoring hardware, updating models, applying security patches, keeping an eye on load. With a cloud model, the provider takes care of this. Costs shift accordingly: locally you mainly pay for hardware and support, in the cloud for actual usage.
How does AI on your own server work with a cloud model?
The second option separates data storage from computing power. Application, knowledge base, templates and histories live on your server. Only when a task requires it does the relevant snippet go to a provider’s language model, and the answer comes back. You keep control of your data store while still using the most capable models.
What matters is the terms under which the provider processes the data it receives, and consumer and business offerings differ considerably. One example: according to its documentation, OpenAI does not use data sent through its API to train its models unless the customer explicitly opts in, a rule that has applied since 1 March 2023. Since February 2025, OpenAI business customers can also choose processing in Europe for eligible API endpoints.
Such commitments do not replace your own review. But they explain why option B is the pragmatic middle ground for many companies: the knowledge of the business sits centrally in-house, the model can be swapped, and you decide task by task which data goes where. Tasks involving particularly sensitive data can additionally be routed to a local model.
Which kind of local AI suits which need?
The overview below sets the usual options side by side. It does not replace a case-by-case review, but it shows where the approaches genuinely differ.
| Aspect | AI chat in the browser (cloud) | System in-house, model from the cloud | Model fully local |
|---|---|---|---|
| Where is your data? | With the provider | On your server, snippets go to the provider for processing | Entirely on your server |
| Where does the model run? | With the provider | With the provider | On your hardware |
| Capability | Current large models | Current large models, your choice | Open-weight models, usually smaller |
| Hardware | None | A standard server | Server with powerful GPUs |
| Maintenance | Provider | Application with you or your service partner, model with the provider | Everything with you or your service partner |
| Data protection | Check contract, settings and how staff use it | Data processing agreement, processing location, training excluded | No external processor for the model, other duties remain |
| Costs in general | Licence per user | Running the application plus model usage | Hardware, power and support |
| Best for | Individual tasks without sensitive data | Broad use across the business with high quality | Highly sensitive data, isolation from the internet |
Is local AI automatically GDPR-compliant?
No, but it makes many things easier. On 6 May 2024, the Datenschutzkonferenz, the body of Germany’s data protection authorities, published guidance on AI and data protection. It distinguishes closed systems, where processing takes place in a contained environment and users keep control of inputs and outputs, from open systems that a provider runs as a cloud service, for example. From a data protection perspective, it considers technically closed systems preferable.
If you use an AI application from an external provider, the guidance says there is often a processor relationship under Art. 28 GDPR, which requires a corresponding agreement with the provider. You should also check whether inputs and outputs are used for training and exclude this where possible. If data goes to countries outside the EU, the rules in Chapter V of the GDPR apply.
For the USA, an adequacy decision by the European Commission has been in place since 10 July 2023: the EU-US Data Privacy Framework. It permits transfers to recipients certified under the framework. The EU General Court upheld the decision on 3 September 2025, and an appeal was lodged with the Court of Justice on 31 October 2025. If you rely on transfers to the USA, keep an eye on the case; option A and processing in Europe make you less dependent on it.
Some duties apply wherever the model runs: a legal basis for processing, informing the people concerned, honouring their rights and, where a high risk is likely, a data protection impact assessment under Art. 35 GDPR. The German authorities state that this will frequently be the case when AI applications are used. On top of that, the AI Act’s AI literacy obligation has applied since 2 February 2025, which we explain in our article on the AI literacy obligation under Article 4.
How do you choose between local AI and a cloud model?
“Local or cloud” rarely has one answer for the whole company. It makes more sense to decide task by task. These questions help:
- 01
01
Which data is involved?Personal data, health data, contracts or trade secrets need more protection than public product copy. The more sensitive the data, the stronger the case for a local model or a provider that processes in Europe.
- 02
02
What quality does the task need?Pre-sorting and summarising work with smaller models too. Where the output goes to customers or requires expert knowledge, the large models are worth a look.
- 03
03
Who looks after the technology?A local model needs someone responsible for hardware, updates and security. If you lack that capacity in-house, a service partner has to provide it.
- 04
04
How dependent do you want to be?If the application and your knowledge stay with you, you can switch models later without starting over. That freedom often matters more than picking a particular provider today.
- 05
05
What does your data protection officer say?Involve your data protection officer before setting anything up, not afterwards. The German authorities’ guidance works well as a shared checklist.
How do we bring local AI into your business?
Our AI agent system follows option B and keeps option A open. The system and your files sit on your server. You decide which language model does the work: a high-quality cloud model, a local open-weight model or both, depending on the task. That means you are not tied to any single AI provider.
The system gets to know your business, works with the software you already use and prepares work that a person reviews and approves before anything goes out. Which data may go to which model is something we clarify with you and your data protection officer before we set anything up.
To help your team use the new capabilities safely, we accompany the rollout with AI training tailored to the tasks in your business. If you use AI in customer contact, for example as a chatbot, also read our article on AI disclosure for chatbots.
Frequently asked questions
What is the difference between local AI and on-premise AI?
Strictly speaking, both mean the same: the language model runs on hardware you operate or control. In everyday use, however, “local AI” also describes set-ups where only the application and data are in-house and the model comes from the cloud. So always ask where the model runs.
What hardware do I need for a local LLM?
It depends on model size. OpenAI states that its smaller open-weight model, gpt-oss-20b, runs within 16 GB of memory, while the larger gpt-oss-120b fits on a single GPU with 80 GB of memory. Several simultaneous users need extra headroom.
Is local AI as good as ChatGPT?
For many everyday business tasks, open-weight models are good enough. They are usually smaller than the large cloud models, though, and according to OpenAI have less world knowledge and hallucinate more. For demanding tasks, compare both on your own real examples.
Do I need a data processing agreement for a cloud model?
Often, yes. According to the German data protection authorities’ guidance, an external provider running an AI application for you frequently acts as a processor under Art. 28 GDPR, in which case a corresponding agreement is required.
Will my prompts be used for training?
That depends on the provider and the plan. OpenAI, for example, says in its documentation that it does not use API data for training unless the customer opts in. Consumer accounts may follow different rules. The German authorities recommend checking training use and excluding it where possible.
Is AI without the cloud automatically GDPR-compliant?
No. It avoids an external processor for the model and transfers to third countries. A legal basis, transparency, data subject rights and, where required, a data protection impact assessment remain your responsibility.
How to find the right route to local AI
- 01
List your tasks
Write down the tasks where AI should save your team time, and note for each one which data is involved.
- 02
Classify your data
Agree with your data protection officer which data may leave the company, which may only go to the EU and which must stay in-house.
- 03
Test both options
Try typical tasks with an open-weight model and with a cloud model, and compare the results on real examples.
- 04
Settle operations
Decide who is responsible for the application, updates and security, in-house or through a service partner.
Local AI is not a matter of ideology but of tasks and data. Once you know which information may leave the building, you can choose the technology accordingly and stay flexible as models and rules change.
Google spam updateGoogle Spam Update: What Can Your Numbers Really Tell You?
LLM costsLLM Cost Optimization: When a Model Switch Pays Off
Detect AI-written textDetect AI-written text: what AI detectors get wrong
AI agentsAgentic AI Explained: What It Means for Your Business
Google AI ModeGoogle AI Mode: What It Means for Your Website
AI agentsWhat Is an AI Agent, and How Is It Different From a Chatbot?
Structured DataStructured Data: What It Really Does for AI Search
AI AssistantAI Assistant for Business: Types, Uses and Data Protection
GEOE-E-A-T: Trust Signals for Google and AI Search
GEOAI Crawlers in robots.txt: Managing GPTBot and Co.
AI for SMEsAI for SMEs: How to Introduce AI Step by Step
Perplexity SEOPerplexity SEO: How to Get Your Site Cited as a Source
ChatGPT SEOChatGPT SEO: How to Get Your Business Found in ChatGPT
llms.txtllms.txt: What the File Does and When It Pays Off
AI SEOAI SEO: What Changes Compared to Traditional SEO
AI OverviewsGoogle AI Overviews: How Google Picks Its Sources
GEO vs AEO vs LLMOGEO vs AEO vs LLMO: The AI Search Terms Explained
Measure AI VisibilityMeasure AI Visibility: Method, Metrics and Limits
ChatGPT AdsChatGPT Ads: How to Advertise on ChatGPT in Germany
AI Literacy ObligationAI Literacy Obligation: What Article 4 Requires Since 2026
AI DisclosureAI Chatbot Disclosure: Article 50 in Practice
AI Text WatermarkAI Text Watermark: What Claude Marks and What It Doesn't
ShopwareShopware Plugin Development: Buy or Build? A Guide
Where the information on this page comes from
- German Data Protection Conference (DSK): Guidance on AI and data protection (6 May 2024, German)accessed 25 Sep 2026
- Oppenhoff: DSK publishes guidance on AI and data protection (German)accessed 25 Sep 2026
- Noerr: AI and data protection, DSK guidanceaccessed 25 Sep 2026
- OpenAI: gpt-oss auf GitHubaccessed 25 Sep 2026
- Hugging Face: openai/gpt-oss-120baccessed 25 Sep 2026
- OpenAI: gpt-oss-120b & gpt-oss-20b Model Card (arXiv)accessed 25 Sep 2026
- TechCrunch: OpenAI launches two open AI reasoning modelsaccessed 25 Sep 2026
- MIT Technology Review: OpenAI has finally released open-weight language modelsaccessed 25 Sep 2026
- Hugging Face: DeepSeekaccessed 25 Sep 2026
- Hugging Face: Qwenaccessed 25 Sep 2026
- OpenAI: Data controls in the OpenAI platformaccessed 25 Sep 2026
- TechCrunch: OpenAI will no longer use customer data to train its models by defaultaccessed 25 Sep 2026
- OpenAI: Introducing data residency in Europeaccessed 25 Sep 2026
- TechCrunch: OpenAI launches data residency in Europeaccessed 25 Sep 2026
- Hesse Data Protection Authority: Adequacy decision on the EU-US Data Privacy Framework (German)accessed 25 Sep 2026
- Lower Saxony Data Protection Authority: New adequacy decision for transfers to the USA (German)accessed 25 Sep 2026
- IAPP: European General Court dismisses Latombe challengeaccessed 25 Sep 2026
- Hunton: EU General Court confirms adequacy of EU-U.S. Data Privacy Frameworkaccessed 25 Sep 2026
- WilmerHale: European Court of Justice to review challenge to EU-US Data Privacy Frameworkaccessed 25 Sep 2026
- Digital Policy Alert: Latombe filed appealaccessed 25 Sep 2026
- EU AI Act: Article 4 AI literacyaccessed 25 Sep 2026
- Mayer Brown: AI literacy requirements come into effectaccessed 25 Sep 2026


