Should I use a public AI API, a privately hosted model, or a managed platform?
Contrasting
Start from Cloud First and consider public cloud, but choose private or tightly controlled hosting when data sensitivity or model control requires it. Public APIs still send data to a provider; private hosting keeps data in an environment you own.
Technology Code of Practice: consider public cloud first. AI Playbook: private hosting keeps organisational data in an environment you own.
How to navigate this: Document why private hosting is needed when departing from Cloud First defaults.
From the guidance
Contrasting Technology Code of Practice
Section: 5. Use cloud first
Contrasting AI Playbook for the UK Government
Section: Privately hosted AI models
Read this in AI Playbook for the UK Government (opens in new tab)
Related questions
- Can attackers steal my model or training data through the API?
- How should I threat-model an AI system?
- What controls do I need when calling an external AI API?
- Can I put official or unpublished information into public tools like ChatGPT?
- How do I stop an AI system from leaking personal or sensitive data?