Blog
Notes on private AI, written by the people building it
How we think about building it.
Enterprise AI search: what it is and how to evaluate it
What it is, how the data is kept separate, and the tests that show whether it works outside a demo.
Enterprise RAG: build versus buy responsibly
Who ends up owning the engineering if you build it yourself.
How accurate is AI on legal questions?
An accuracy figure means little without the corpus and the questions behind it. What to measure instead, and why the no-answer cases tell you most.
How AI reads a legal document, stage by stage
The model is the fifth stage of five, and rarely the one that decides whether an answer is any good. What happens before it, and where each step falls over.
Privilege, barriers and AI over your documents
Vendors answer the information barrier question in one sentence about permissions. That sentence covers three architectures that do not protect you equally.
What in-house legal teams need from AI
The in-house bottleneck is usually finding what you already agreed, not drafting faster. Most of the market is built to sell against the other problem.
What ISO 27001 tells you about an AI vendor
ISO 27001 is a security claim you can verify before signing. What the certificate covers, what it leaves out, and which questions to ask an AI vendor.
Private RAG, explained for software buyers
Private RAG is not a standard assurance label. Which boundaries to check on retrieval, on hosting and on your own data before you sign anything.
Why cited answers beat confident answers
A citation makes an AI answer checkable, but its presence does not prove the answer is right. How to test what one supports before you rely on it.
Occasional notes on private AI
New posts land in the feed. No list, no sequences, and nothing to unsubscribe from.