Decide where confidential documents can be summarised by checking permission, processing location, retention, device limits and the work needed to verify results.

Direct answer: Use an approved cloud service only when permission, access and retention terms cover the actual document and account you will use. If the material must remain on an approved device, consider a verified local workflow, provided that device can run it and protect the resulting files. When neither route meets those conditions, summarise manually in the authorised environment rather than moving the document to make AI convenient.

The label “local” answers only part of the question. An application can process text on your laptop while its output is saved into a synchronised folder, included in a backup or exposed through a shared account. Conversely, a properly approved cloud arrangement may offer administration and recovery that an unmanaged personal laptop lacks.

The decision therefore starts with the document's permitted boundary, not a universal privacy ranking. How to Choose the Right AI Tool Without Being Sold by the Demo covers general task fit. This article uses the document boundary check, an editorial method that follows one file through processing, review, storage and removal.

Applies to: individual professionals and small teams handling confidential documents. This is a documentation-based decision method, not a security certification or hands-on comparison of models.

Start with permission before opening the tool

Name the person or policy that controls the document. You need to know whether the permission covers external processing, copying onto another device and retaining derived notes. Access to a board pack does not automatically authorise uploading it into a personal account.

Ask a concrete question: may this particular document, containing these types of information, be processed in this service and account? “Can we use AI?” is too broad. The answer could differ for a published report, a draft acquisition proposal and staff-related records in the same folder.

If personal data is involved in UK work, use the organisation's data-protection process before selecting a tool. The ICO's AI guidance is relevant, but the regulator currently flags it as under review following legislative changes. Requirements vary by country, sector and contract; ask your responsible privacy adviser about a specific uncertain disclosure.

Until permission is clear, test with a synthetic document. Copy its structure, such as headings, tables and exception clauses, without copying confidential facts. You can learn whether the interface and review process work without exposing the real pack.

Follow the document boundary check

Draw the actual path as a short sequence: source file, application, processing location, stored conversation, exported summary and eventual deletion. Mark any step that sends a copy to a new organisation, account or device.

At each step ask who can access it, what persists and who can remove it. A blank answer is a reason to pause. This is an editorial rejection gate, not a technical standard or proof that a completed diagram makes the system secure.

Include components beyond the visible chat. A browser extension, connected drive or remote transcription feature can introduce another party. For a local setup, check optional integrations and server features instead of assuming the word “desktop” describes every operation.

LM Studio provides one documented local example. Its offline-operation documentation says downloaded models and document processing can run locally without connectivity. The same page distinguishes that work from model downloads, discovery and update checks that need internet access. These are vendor-described boundaries, not evidence from an independent inspection of your installation.

An offline trial with synthetic data can establish that the chosen task still functions without a connection. It cannot establish everything the application might do when connectivity returns. For a strict workplace restriction, have the approved technical owner verify the whole configuration.

Compare the actual operating arrangements

ArrangementInformation boundaryAdministration burdenUseful default
Approved local AIProcessing can remain on the permitted device if the full configuration supports itYou or your IT owner manage software, models, stored output and device recoveryMaterial cannot leave the device and the task works adequately there
Approved cloud AIContent is sent to the provider under the applicable service termsYour organisation must manage account permissions, retention and supplier approvalThe documented arrangement permits the material and supports the work
Manual local summaryNo AI upload is needed; normal file and device controls still applyReview and note storage remain your responsibilityAI adds unacceptable exposure, setup or verification effort

My default for a one-off confidential board pack is to keep the authorised manual process unless an approved AI route already exists. Building a new local installation immediately before a meeting can add an unexamined system at precisely the wrong time.

The strongest case for local AI is a recurring workload with a firm restriction on external processing and a supported device. The strongest case for approved cloud AI is a team that needs managed access and reliable administration without maintaining local models. Neither case removes the need to check the summary against the source.

Check the laptop without buying hardware on speculation

A model file occupying storage is not the same as the working memory required to run it. Working memory is the temporary space applications use while operating. A downloaded model fitting on disk does not establish that it will respond acceptably alongside your normal applications.

Check the application's current system requirements against the exact device and operating system. LM Studio's requirements page distinguishes supported platforms and hardware considerations. Treat those as entry conditions, not a promise of performance for your chosen model and document.

Then use the synthetic pack while your normal work applications are open. Record whether the model loads, whether document processing finishes and how much intervention the summary requires. If it fails, preserve the error text and configuration for the technical owner rather than randomly increasing settings.

Work through the storage and download cost

Imagine a supported work laptop with 18 GB of available storage. These are illustrative assumptions, not LM Studio specifications: the selected model needs a 5 GB download, application and runtime files need another 2 GB, and working documents and outputs need 1 GB.

The planned additional storage is 5 + 2 + 1 = 8 GB, leaving 18 − 8 = 10 GB. That remaining space must also accommodate the laptop's ordinary work and updates. The arithmetic does not establish that 10 GB is enough; compare it with your organisation's requirements and expected growth.

Assume the model download maintains 20 megabits per second. Using decimal units, 5 GB × 8 = 40 gigabits, or 40,000 megabits. The ideal transfer time is 40,000 ÷ 20 = 2,000 seconds, approximately 33 minutes 20 seconds, before connection variation and overhead.

If the meeting starts in 25 minutes, downloading and configuring this model is not a credible preparation plan. If the model is already installed and approved, that cost has already been incurred. The example shows why timing and existing infrastructure can change the recommendation without making either architecture universally superior.

Verify retention as carefully as training use

Ask separate questions about model training, conversation storage, file storage, staff or administrator access, and deletion. “Not used for training” does not mean the provider never stores the document.

OpenAI's data-use guidance distinguishes individual-service choices from business-service defaults. Its separate retention policy describes deletion timing and exceptions. Those pages are examples of the distinct checks needed, not blanket approval to upload confidential work to ChatGPT.

For local AI, identify where the application stores chats and document indexes. Check whether the device's backup or synchronisation includes that location. Do not delete files merely to experiment with cleanup; first save the authorised work you need and follow the application's documented removal process.

The summary inherits the sensitivity of what it reveals. A short paragraph naming a planned acquisition can be just as confidential as the original report. Give it the same review and storage attention instead of treating generated text as harmless output.

Make a bounded decision before the next pack

  1. Spend 20 minutes documenting the permitted location and responsible owner before any upload or installation.
  2. If an approved route exists, reserve an hour for a synthetic pack trial, including setup and manual comparison of names, figures, conditions and source references.
  3. Record the real processing path and the removal procedure with the person responsible for the device or service. Resolve missing answers before using confidential material.
  4. Choose local AI, approved cloud AI or manual work based on permission and the usable result. Recheck when the account, integration or document sensitivity changes.

Stop if approval is missing, the processing path cannot be established or the output needs more reconstruction than direct reading. Keeping the manual process is a completed decision, not a failed adoption project.

Frequently asked questions

Does disconnecting Wi-Fi prove that a local AI application is private?

No. It can show that a particular operation works without a network connection, which is useful evidence about immediate dependence on a cloud service. It does not prove what the application stores, which other users can access the device, or what might synchronise later. Run any initial check with synthetic material and inspect the application's documented behaviour. A workplace rule requiring strict isolation may need technical controls and review beyond a user-level test. Do not disable security protections or required device management to obtain a seemingly cleaner offline result.

Can I remove names and then upload a confidential document?

Removing names is not automatically sufficient. A distinctive role, event, amount or combination of facts can still reveal the person or organisation, and commercial confidentiality may remain even where no individual is identifiable. Start by asking whether an approved redacted excerpt is adequate for the task. Have the document owner confirm the permitted use instead of making the decision from appearance alone. For a trial, synthetic information is usually easier to control. Where UK personal data or contractual restrictions are involved, use the responsible privacy or legal adviser to resolve the particular uncertainty.

Is an open-weight model automatically suitable for commercial work?

No. Available model files do not establish unrestricted licensing or permission for your intended activity. Check the licence attached to the exact model and distribution, including any applicable use conditions, before adopting it for work. Also distinguish the model licence from the application terms and the rights governing the documents you process. This article does not recommend a particular model or claim that open weights mean open source. If the terms are unclear or the consequence matters commercially, ask the model publisher or a qualified adviser before building a recurring workflow around it.

Can a local model summarise a scanned board pack?

Possibly, but that depends on the model, application and document-processing path. A scan may need optical character recognition, which converts page images into machine-readable text, or another verified method of interpreting images. Check where that conversion happens because a supposedly local workflow could introduce an external service at this step. Test a synthetic scan containing the same types of tables and small print. Confirm names, negative statements and numbers against the visible pages. If text is missing or rearranged, repair the input through an approved method before trusting a summary built from it.

Should every member of a small team install a local model?

Not necessarily. Multiple installations create multiple copies of software, models and potentially confidential outputs to maintain. First establish who actually needs the task and who can support the devices. A small approved pilot may reveal that only one role benefits, or that a managed existing service better fits the team's access requirements. Shared processing on another machine introduces its own permissions and network boundary, so it is not simply equivalent to personal offline use. Choose the arrangement your team can operate and recover, rather than distributing an installation because it appears easy to download.

What should I keep after deleting the AI conversation?

Keep the approved final summary, its original source references and enough information to understand how it was checked, following your organisation's retention rules. You do not necessarily need every experimental draft. Decide this before cleanup so deletion does not remove evidence needed to correct a decision. Verify separately whether uploaded files, exported notes or local indexes persist after removing the visible conversation. The right record depends on the work and jurisdiction, not a universal retention period. If policy requires removal of all derived copies, coordinate that requirement with the document owner rather than keeping a private archive.

Sources and verification

Twokq Tech

This article is practical guidance. Apply it in proportion to your tools, evidence, risks, and responsibilities.