Public vs. Private AI: What Most Organizations Don't Know

That $20 a month subscription your employees are using is public AI. Not private. A federal court ruled in February 2026 that documents created in a public AI platform destroyed attorney-client privilege. Most organizations don't know this yet.

In April I attended IterateOn, an invite-only AI symposium for enterprise leaders.

I walked in thinking I understood the AI landscape reasonably well. Two years of running production deployments at scale. Real experiments. Real stakes. Real outcomes.

I walked out knowing something I didn't know when I walked in.

Most organizations have no idea what kind of AI they are actually running.

Private AI means the organization controls three things: the compute environment, the model itself, and the data that flows through it. That control exists on a spectrum. True private AI runs on dedicated infrastructure with full ownership of models and data. A properly architected private cloud deployment can provide meaningful protection if configuration is verified and contractual terms are airtight. What most organizations actually have is somewhere in the middle. Partial isolation. Protections assumed but not verified.

Public AI sits at the other end. Consumer tools like ChatGPT, Claude.ai, Google Gemini, and standard versions of Microsoft Copilot. You control none of those three things. Your input goes to the AI company's servers, governed by their terms of service, which typically permit data collection, storage, and disclosure to governmental authorities.

That $20 a month subscription your employees are using right now is public AI. Not private. About as confidential as a conversation in a coffee shop.

That distinction moved from interesting to urgent in February 2026.

A federal judge in the Southern District of New York ruled in United States v. Heppner that documents created using a public AI platform were not protected by attorney-client privilege. A financial services executive typed his attorney's advice into a consumer AI platform. The court ruled the privilege was gone the moment he hit enter. Not just the AI output. The original legal advice itself.

Enterprise doesn't automatically mean private.

Most organizations that believe they have protected AI deployments have not verified what that actually requires. A signed data protection agreement. A confirmed zero training configuration. Infrastructure that keeps your data separated from other tenants. Most Copilot deployments don't meet all three. Most IT teams have assumed rather than verified.

A signed contract tells you what recourse you have after something goes wrong. It does not guarantee that nothing will.

The distinction between public and private AI needs to be policy. Not assumption.

The Technology Wave Playbook — a framework for translating AI and emerging technology into durable competitive advantage.

Download Free →