Skip to main content

We use cookies to improve your experience and measure traffic. Decline to opt out of analytics and advertising cookies. Cookie preferences

For organisations whose risk, legal or procurement team asks where the model runs

Private AI Deployment in Australia: Inside the Tenancy You Already Own

Two years ago the AI question in an Australian boardroom was whether to use it at all. Now the question is narrower and much harder to answer with a straight face: where does the data go, whose law can reach it, and what happens to it after the answer comes back. Staff are already pasting client material into consumer chat tools, and the honest response to that is not a policy banning it. It is a sanctioned place to do the same work.

The line we draw publicly, because too many vendors blur it: we deliver AI that runs inside the Microsoft 365 or Google tenancy you already pay for, in an Australian region where the platform actually offers one, with no training terms written into your contract rather than promised on a marketing page. We do not rack hardware, we do not host GPUs, and we do not operate model serving infrastructure. That is a data centre business and pretending otherwise would be dishonest.

Realistic ROI

Three questions
Decide most Australian AI security reviews
Where the data is processed, whose law can compel access to it, and whether the provider trains on your content
Per service
Is how region availability actually works
A vendor having an Australian presence does not mean the specific AI feature you want runs here, and the answer changes as products ship
Zero new vendors
When the work runs in a tenancy you already licence
The supplier has already cleared onboarding, which removes the slowest step in most procurement cycles
In the contract
Is the only place a no training promise counts
Product pages change without notice; the data processing terms attached to your agreement are what an auditor or a regulator will read

Four Things That Decide Whether a Deployment Is Actually Private

Almost every argument about private AI is really an argument about four separate questions that get collapsed into one word.

Private is a set of controls, not a feeling

When a client says they want private AI, they usually mean four different things at once: our data should not leave our subscription, it should not be stored longer than we allow, it should not be used to improve someone else’s model, and only the people who could already see a document should be able to ask questions about it. Those are four separate controls, configured in four different places, and a deployment can satisfy three of them while quietly failing the fourth. Write them down as four line items and test each one, because a single word in a proposal cannot be audited.

Where it runs is a per service question, not a per vendor one

The two productivity clouds are not equivalent here, and averaging them is how buyers get caught. Microsoft 365 supports Australian data residency, with Australia as a local region geography covering Exchange, SharePoint, OneDrive, Teams and Copilot. Google Workspace does not currently offer an Australian data region at all: as at August 2026 its data regions setting covers the United States or Europe only, which is a material difference if you are on Workspace and residency is a stated requirement. Even where residency is available, the commitment does not automatically extend to every AI feature the vendor ships, because new capability often launches in a limited set of regions first and expands later. The only reliable method is to name the specific workload, check the current published residency position for that workload, and record the date you checked. We have seen a control described as settled in a risk register that had been overtaken by a product change six months earlier.

Residency, sovereignty and sovereign AI are three different things

Data residency is where the bytes physically sit. Sovereignty is which country’s legal system can compel a provider to hand them over, which depends on where the provider is incorporated and who controls it rather than where the disk is. Sovereign AI is a third thing again: who controls the model, the weights and the stack it runs on. Australian residency is achievable today for most mainstream workloads. Full sovereignty over a model built by a foreign company is not something any consultancy can hand you, and anyone claiming otherwise is selling a word rather than a control.

A no training promise has to be contractual and specific

Nearly every serious enterprise AI product now states that customer content is not used to train foundation models. That is genuinely the default at the business tier and it is a real change from the consumer products. The problem is that the statement often lives on a web page rather than in your agreement, and it may carve out abuse monitoring, human review of flagged content, or a different position for preview features. Ask for the clause, read what it excludes, and note the retention period for any content held for safety review. If the answer is only a link to a marketing page, you do not have a control, you have a hope.

What a Private Deployment Actually Consists Of

Six controls. Each one is separately configurable, separately testable and separately capable of failing.

Runs on your subscription

The tenancy boundary

The processing happens inside the Microsoft 365 or Google environment your organisation already owns, under your commercial agreement, your admin controls and your existing data processing terms. This is the single highest value decision in the whole exercise, because it means you are not adding a new data processor, a new subprocessor chain or a new set of terms to your vendor register. Most of the security review has already been done, which is why these projects clear governance in weeks rather than quarters.

Stored in Australia

Region and residency

The tenancy is pinned to an Australian region and each AI workload is checked individually against the provider’s current published residency commitment for that workload. Note that the durable commitment is about data at rest. Microsoft states that an individual request may on occasion be handled by servers outside your region even while the data at rest stays put, so if your requirement is that processing never leaves Australia, say so explicitly and check it as a separate question. Where a capability cannot yet run in an Australian region, you get told that plainly and you decide whether the workload waits or proceeds with the exposure documented. What we will not do is describe a global service as Australian because the company has a Sydney office.

Answers respect access rights

Identity and permissions

Access runs through the identity provider you already use, with the same groups, the same conditional access and the same multi factor requirements as everything else. Critically, anything that reads your documents must inherit the permissions on those documents, so a user cannot get an answer assembled from a file they are not allowed to open. Over broad file sharing inside the organisation is the most common reason this control fails, and it is a pre existing problem that AI merely makes visible.

Held only as long as you allow

Retention and deletion

Prompts, responses, conversation history and any index built over your content all have retention settings, and the defaults are rarely what a records manager would choose. Decide how long each is kept, whether it falls inside your existing retention and disposal schedule, and what happens on an employee’s exit or a legal hold. Also decide who can see the history, because an admin who can read every prompt is a privacy exposure your staff will assume does not exist.

Written, not implied

Contract terms

The data processing terms should state that your content is not used to train foundation models, name the subprocessors, state the retention period for any content held for safety or abuse monitoring, and set out breach notification obligations. Read the exclusions rather than the headline. Preview and beta features frequently sit under different terms, which matters because the useful new capability is usually the one in preview.

Provable after the fact

Logging and audit

An auditor will ask who used the system, what they asked, what sources were used to answer and whether anything was exported. Your tenancy already produces most of that telemetry through its native audit log, which is another argument for staying inside it. Confirm the retention period on the audit trail itself, because it is often shorter than the retention people assume, and a control you cannot evidence six months later is not much of a control.

What Changes When AI Runs Inside Your Own Environment

TaskTraditionalInside your tenancyNotes
Where the data is processedWherever the consumer product routes itA region you selected and can evidenceThe change is not the region alone, it is that you can now answer the question at all.
Whose agreement covers itTerms an employee accepted personallyYour existing enterprise agreementConsumer terms are accepted by the individual, which means the organisation has no contractual position to enforce.
Training on your contentDepends on the tier and the settingsContractually excludedBusiness tiers generally exclude it, consumer tiers often do not. The tier matters more than the brand.
Who can see an answerWhoever pasted the document inOnly users with rights to the sourcePermission inheritance is the control that makes internal knowledge search safe to switch on.
Access controlA separate password per staff memberYour identity provider and existing groupsOffboarding then works the same way it does for everything else, which is the point.
Retention of promptsUnknown and unmanagedSet deliberately and documentedBring it inside the retention and disposal schedule you already maintain rather than inventing a parallel one.
Evidence for an auditNone that you controlNative tenancy audit logsCheck the log retention window early. It is usually shorter than people expect.
Adding a new use caseAnother tool, another reviewSame boundary, same controlsThe governance work is done once, which is what makes the second and third use case cheap.

Where Private AI Projects Go Wrong in Australia

Assuming the tenancy setting covers the AI feature

Organisations pin their tenancy to an Australian region for mail and files, then assume every AI capability inherits that. Newer features often launch in a limited set of regions and expand later, and preview capability may sit outside the residency commitment entirely. Check the residency position for each specific workload, record the date and the source, and re check when the provider ships a major update. A control recorded once and never revisited is how risk registers quietly go stale.

Confusing residency with immunity from foreign legal process

Storing data in Sydney does not by itself put it beyond the reach of a foreign legal order, because jurisdiction generally follows the provider and its corporate control rather than the location of the disk. For most Australian commercial organisations this is an acceptable, disclosed risk rather than a blocker. For sensitive government work, national security adjacent data or certain regulated datasets it may not be, and that decision belongs with your legal advisers rather than with an implementation partner.

Over broad file permissions being exposed rather than created

The moment you point a retrieval tool at a document library, everything that was accidentally shared with the whole organisation becomes findable in one sentence. The salary spreadsheet in a team site that someone opened up in 2019 was always exposed. It was just protected by nobody knowing the filename. Run a sharing and permissions audit before you index anything, and treat remediation as part of the project rather than a separate initiative someone will get to later.

Treating a marketing claim as a contractual term

The sentence you need is in the data processing addendum, not the product page. Ask specifically whether customer content is excluded from foundation model training, what content is retained for abuse monitoring and for how long, whether human reviewers can access flagged content, which subprocessors are involved and where they operate. Then check whether preview features are carved out. Vendors answer these questions readily when asked in writing, which is exactly why you should ask in writing.

Nobody owns the Australian Privacy Act analysis

If the material includes personal information, the Privacy Act obligations do not go away because the processing is clever. You still need a lawful basis for the use, notice that reflects what actually happens, an answer on overseas disclosure, and a way to handle access and correction requests when the information sits inside an index rather than a file. A short privacy impact assessment before go live is far cheaper than an after the event one, and reform activity in this area means the position deserves a fresh look rather than a copy of a 2021 assessment.

Buying a private deployment for a problem that is not private

A meaningful share of the AI work an organisation wants involves public information: market research, drafting from a blank page, summarising a published document. None of that requires the extra cost and friction of a locked down deployment. Sorting your use cases by data sensitivity first usually shows that the genuinely sensitive set is smaller than expected, which makes it cheaper to protect properly. Spending the private deployment budget on public information work is a common and avoidable waste.

How Yes AI Approaches Private Deployment

We start with your tenancy, not our platform

The first session is an inventory of what you already licence, what regions you are pinned to, how sharing is configured and which of your use cases actually touch sensitive information. Very often the capability you want is already inside a subscription you pay for and simply has not been turned on or governed properly.

Controls written as line items an auditor can test

Region, identity, permission inheritance, retention, training exclusion and audit logging each become a stated control with a stated evidence method. You end up with something your risk team can sign rather than a paragraph of reassurance.

A clear line about what we do not do

We do not rack hardware, host GPUs or operate model serving infrastructure, and we will not let a proposal imply that we do. If your requirement is genuinely on premise model hosting, that is an infrastructure engagement and you need a different kind of partner. Everything we deliver runs inside a tenancy you already own.

Honest advice on when not to do this

If your use cases are all public information, or your organisation is small enough that a well configured business tier subscription with good policy covers it, we will say so. Private deployment work earns its keep when you have genuinely sensitive material, a procurement process that asks these questions, or a regulator who will.

From First Question to a Deployment Your Risk Team Signs

Five steps. The slow part is almost always the permissions clean up, not the technology.

Sort the use cases by data sensitivity

We split what you want to do into public information work, internal but low sensitivity work, and material that would cause real harm if it leaked. Only the third group justifies the full control set, and knowing that early saves both money and argument.

Establish the tenancy position

Which subscriptions you hold, which regions you are pinned to, how identity and conditional access are configured, what your current sharing posture looks like, and what your data processing terms actually say today.

Fix permissions before anything is indexed

A sharing audit across the libraries in scope, remediation of anything open to the whole organisation that should not be, and a documented owner for each site. This is the step people want to skip and the one that decides whether the result is safe.

Configure, document and evidence each control

Region, permission inheritance, retention, audit logging and the contractual training exclusion each set deliberately and written up with the evidence method, so the control set can be handed to an auditor without a translation layer.

Pilot with a named group, then widen

One department, a bounded content set, weekly review of what was asked and what was returned, and a decision point before extending. Usage patterns from the pilot almost always change the second phase scope.

FAQ

Answer the Three Questions Before Someone Asks Them

Book a call. We map your use cases against your existing tenancy, tell you which controls you already have and which you do not, and give you a plan your risk team can sign. Priced after scoping.

All discussions held in confidence. Australian-based consultants.