The AI risk is not only the model

AI exposure comes from the full operating pattern: prompts, uploads, chat history, retrieval indexes, connectors, logs, source permissions, output reuse, model routing, administrative access, and whether customer content can be used to train or improve external systems.

What private AI control should cover

  • Prompt, upload, output, and log handling by data category.
  • Retrieval-augmented generation with source permissions and records policies respected.
  • Model routing rules that separate sensitive, internal, and public use cases.
  • Token-spend governance so AI consumption does not become an unmanaged variable cost.
  • Self-hosted Mistral deployment where the use case requires customer-controlled infrastructure.

Where DCS starts

The first step is usually an AI exposure assessment across Microsoft Copilot, Google Gemini, ChatGPT, Claude, Grok, and adjacent services, followed by a pilot private AI assistant for a controlled workflow such as board materials, policy search, secure records review, or internal knowledge retrieval.