Some of what your business handles cannot be posted to an API in another
country, and no amount of vendor reassurance changes that. For that
slice of the work, the model comes to the data instead.
In short: yes, an Australian small business can run AI on
infrastructure it controls. Open-weight models now run usefully on a single
well-specified server, either on your own hardware or on a machine you rent
in an Australian data centre, so confidential information never leaves that
boundary. It is not the right answer for everything: the practical approach
for most businesses is a split, with commercial AI doing the bulk of the
work and a private deployment handling only the data that genuinely cannot
leave. AI4SMB runs open-weight models on its own infrastructure and assesses
which side of that line each task belongs on.
The actual question
It is not "is AI safe". It is "which data, going where".
Privacy worries about AI usually arrive as one large vague feeling, and
in that shape they are impossible to act on. So they get resolved the
two unhelpful ways: banning the technology outright, or waving the
concern through because a vendor page said "enterprise grade". Broken
into specifics it is far more tractable. Most of what a business wants
to hand over is not confidential at all. A small slice is. The job is
knowing which slice, and then giving that slice somewhere to go.
Who this is for
Businesses where the answer is not optional.
Allied health and medical practices
Patient records carry a federal layer plus, in Victoria and New South Wales, a state health records act on top. The practical question is rarely "is AI allowed" and almost always "which specific tasks can touch which specific records, and can you show the reasoning later".
Legal practices
Professional obligations around client confidentiality tend to be stricter than the Privacy Act on its own, and they apply to matter files whether or not the information is personal. A split approach usually works: commercial AI for research and general drafting, a private option for anything that touches a matter.
Accounting and financial services
Client financial records, TFNs and identity documents are exactly the category where "where does this go" needs a written answer. This is also the sector where the volume of repetitive document work makes AI most attractive, which is what makes the tension worth resolving properly.
Anyone under a client contract that says so
Plenty of businesses are bound not by legislation but by a clause in a contract with a larger customer. Government and enterprise supply agreements often specify where data may be processed. That clause is as binding as any statute and is frequently the real reason a business needs this.
None of the above is legal advice, and the specifics of your obligations
depend on your circumstances. What we can do is tell you accurately where
data would travel under each option, and document it so that the decision
you make is one you can explain later.
The trade, stated plainly
Running your own model is infrastructure. Treat it as such.
The pitch for self-hosted AI usually stops at "your data never leaves",
which is true and incomplete. You are also taking on a server that has to
be patched, monitored, backed up and kept running, and a model that will
be superseded. Commercial AI is priced per use and scales with your
usage; self-hosted is largely a fixed cost, which makes it look expensive
at low volume and steadily more sensible as volume grows. And the largest
commercial models remain stronger on the hardest tasks, so you are
trading some capability for control. We would rather you hear that from
us and decide with it than discover it after the hardware arrives. Where
we think a business should just use commercial tools, we say so.
Why us
We run this, we do not resell it.
AI4SMB operates open-weight models on its own infrastructure, and has
through the build of this site. That matters because the hard part of
private AI is not choosing a model, it is the operations around it, and
that is ordinary infrastructure work of the kind an MSP has been doing
for 32 years. Being straight about the limit of the claim: we are
not pointing at a client deployment on this page, because publishing one
needs that client's written consent, and this site does not imply proof
it has not shown you. What we are offering is an honest assessment from
people who have run the thing they are recommending.
Private and self-hosted AI, straight answers
Can a small business run AI on its own servers instead of the cloud?
Yes, and it is far more achievable than it was even a year ago. Open-weight models now run usefully on a single well-specified server, which means a business can hold its own model on its own hardware, or on a machine it rents in an Australian data centre, with nothing leaving that boundary. It is not free and it is not the right answer for everyone, but it is a genuine option rather than an enterprise-only one. The trade is capability and cost against control: the largest commercial models are still stronger at the hardest tasks, and you are taking on a piece of infrastructure you now have to run.
Why would I not just use ChatGPT or Copilot?
For most tasks in most businesses you should, and we will tell you that. The question is not philosophical, it is about specific data. If a task involves information you are contractually or legally not allowed to disclose to a third party, then the tool that sends it to a third party is out, regardless of how good it is. That is a small subset of what a business does, which is why the useful answer is usually a split: commercial AI for the bulk of the work, a private option for the narrow slice that genuinely cannot leave.
Where does my data actually go with a normal AI tool?
That is exactly the question to ask, and you should get the answer in writing rather than from a sales deck. What you want to know is where it is stored, which country it is stored in, whether it is used to train anything, who can access it, and what happens to it over time. Vendors vary enormously and their terms change. Under the Privacy Act the obligation to know sits with you rather than with the vendor, which is the part most owners are surprised by.
Does Australian law require me to keep data onshore?
Usually not as a blanket rule, and anyone who tells you otherwise is oversimplifying. The Privacy Act does not generally prohibit sending personal information overseas, but it does make you accountable for what happens to it, and Australian Privacy Principle 8 makes you responsible for an overseas recipient's handling of it in most circumstances. On top of that, health information carries state layers that differ: Victoria and New South Wales have their own health records legislation, while a Queensland private practice largely sits under the federal regime. Professional obligations can bite harder than statute too, particularly for legal practitioners. The honest summary is that it is rarely a flat prohibition and often a documented-risk decision, which is precisely why it belongs in an assessment rather than in a brochure.
Is a local model good enough to be useful?
For the work most businesses actually need, yes. Summarising documents, drafting from a template, extracting structured data from unstructured files, classifying and routing, answering questions against your own material: open models handle all of that well now. Where they still lose to the big commercial models is the hardest reasoning and the longest, most complex tasks. So the practical test is not "is it as good as the best model in the world", it is "is it good enough for this specific job, given that this job cannot go to the best model in the world anyway".
What does this actually cost to run?
It changes the shape of the cost rather than only the size of it. Commercial AI is priced per use, so it scales with how much you do. Self-hosted is mostly a fixed cost: hardware or a rented onshore server, plus the ongoing job of keeping it patched, monitored, backed up and working. That means it tends to look expensive at low volume and increasingly sensible as volume grows. It also means someone has to own it operationally, which is the part that gets skipped and then bites. We would rather quote you the honest running cost than the hardware price.
Do you actually run this yourselves?
Yes. AI4SMB runs open-weight models on its own infrastructure, and has done through the build of this site. That is the basis on which we will discuss it with you: it is something we operate rather than something we resell, and the operational detail we would be advising you about is detail we have had to deal with ourselves. We are being deliberately precise here because this site has a rule against claiming capability it has not demonstrated. What we are not doing on this page is pointing at a client deployment, because publishing one requires that client's written consent and we will not imply proof we have not shown you.
How do I know whether I need this?
Start with the data rather than the technology. Write down the tasks you would most like to hand over, and beside each one write what information it would need to touch. If none of it is confidential, you do not need this page and you should go and use commercial tools. If some of it is, you now know exactly which slice needs a different answer, and how big that slice is. That mapping is part of the AI opportunity audit, and it is usually the point where a vague privacy worry turns into a specific and much smaller problem.
Find out which of your data actually has to stay put.
Book an audit call. We map which tasks touch confidential information and which do not, and you get a written answer about where each one can safely run.