← Back to journal

SYSTEM DESIGN

Private AI needs a boundary you can explain.

A useful privacy conversation follows the data from its source to every place it can go.

Joseph W. Anady · September 28, 2026 · 4 minute read

Draw the route.

Document what enters the system, where processing happens, which services receive information, and what is retained. Include logs, backups, notification services, and evaluation datasets. The conversational interface is only one part of that route.

Define who can see what.

A search or assistant interface must respect the access boundaries of its source material. A technically correct answer can still be the wrong answer to reveal to a particular person. Permissions need to be part of the retrieval and testing design.

Separate the deployment choice from the claim.

Running a model locally changes where inference occurs. It does not, by itself, establish secure operations, correct permissions, or reliable answers. Those are separate questions that require separate evidence.

Give the system an owner.

Specify who updates the sources, changes access, reviews failures, removes information, and verifies that the system still behaves as intended. A clear operational boundary is more useful than an undefined promise of privacy.

THE NEXT CHAPTER

What would you like to make possible?

Start with a conversation about the work, the idea, or the problem you want to solve.

Talk through your project

What are you exploring?

Search the pages and fieldnotes.

Your visit. Your choice.

The painting and the website work without analytics. Optional first-party measurement records page categories and interaction events, not your message, email address, or a cross-site advertising ID.

Your motion and measurement choices can be remembered on this device. Global Privacy Control and Do Not Track override optional measurement.

Read the privacy note