Open AI vs closed AI
Every business is now choosing how it uses AI. This briefing is about one strategic decision — where your AI runs, and what that means for privacy, performance, cost and control. It's written for the boardroom, not the IT department: plain English, one idea per slide.
The decision this briefing is about
Every business is now choosing how it uses AI. Underneath the tool choice sits one strategic decision: where your AI actually runs. That decision drives privacy, performance, cost and control, and it is a board decision rather than an IT one.
Open models are ones you download and run yourself, on your own hardware, so you control the whole environment. Examples include Llama, DeepSeek, Gemma and Qwen. Closed models run on someone else's servers and the provider manages everything. Examples include ChatGPT, Claude and Gemini.
What happens to my data?
This is the first question every board asks, and the honest answer is that it depends on where the model runs.
- Open models. Data stays inside your business. It never leaves.
- Private cloud. Data stays within environments you have approved. It is contained.
- Public AI services. Data leaves your organisation.
Which of those is right depends on four things: the sensitivity of the data, your compliance requirements, your budget, and your tolerance for risk.
Open models: maximum control
The benefits are that data stays local, the system can run fully offline, there are no per-user AI costs, it is fully customisable, and it suits sensitive information. The challenges are that it requires infrastructure, needs more technical management, and usually sits behind the leading cloud models on raw capability.
Closed models: maximum capability
The benefits are the best performance, the fastest innovation, no infrastructure to run, easy deployment and lower technical complexity. The challenges are ongoing subscription costs, less control, and data governance considerations you have to work through with the provider.
Who wins on intelligence?
Closed frontier models still lead today on reasoning, coding, research and complex problem solving. Open models are closing the gap quickly. The ordering shifts month to month, so treat any ranking as directional rather than benchmarked, and avoid building a strategy that depends on one vendor staying ahead.
Which is more secure?
Neither, automatically. An open model keeps data local and gives you greater control, but the security responsibility is entirely yours. A closed model from an enterprise-grade provider comes with a shared responsibility model and strong governance controls you can switch on. Security comes from architecture and implementation, not from the label on the model.
What most businesses actually do
The common pattern is hybrid, and it is becoming the standard enterprise approach. An AI router directs each request based on sensitivity. Open models kept in house handle internal documents, financial data, HR information and contracts. Closed models in the cloud handle research, content creation, analysis and general productivity.
A worked example from construction: the open model handles supplier information, pricing history, project documentation and the internal knowledge base. The closed model handles proposal writing, research, marketing content and general productivity. The result is higher productivity without exposing sensitive business data.
How we help
Four steps. Assess your data, systems and risks. Design the right AI architecture for your business. Deploy secure AI solutions into production. Scale by training your team and improving adoption.
Where the market is heading
Today, employees use AI tools individually. Tomorrow, businesses deploy AI systems integrated into the tools they already run: Microsoft 365, the CRM, the ERP, knowledge bases and workflows. The question is no longer whether to use AI. It is which AI architecture is right for your business.
For SME owners, managing directors, operations and IT leads.
- What open and closed models actually are — without the jargon.
- What happens to your data, on a simple traffic-light view.
- Where each approach wins: control versus capability.
- Why security comes down to architecture, not the label.
- The hybrid pattern most businesses settle on — with a worked example.
- How we help, and the AI readiness assessment as a first step.