What "Private by Design" Should Mean for Enterprise AI

Privacy is not a product claim or a settings page. It is a set of technical and operational choices that determine what an AI workflow can see, retain, and do.


Private by design is becoming a common phrase in enterprise AI. It only helps if it leads to specific design decisions.

Privacy is not established because a vendor says data is protected. It is established through the boundaries a company defines around data, identities, permissions, retention, and review.

Start with data boundaries

Every AI workflow should have an answer to a basic question: what data is allowed to enter?

That answer should be more precise than company data. Useful boundaries distinguish public information, internal operational material, confidential records, regulated data, and credentials or secrets that should not enter a prompt at all.

The point is not to make every workflow restrictive. It is to avoid the assumption that every tool should receive every kind of context.

Access should follow the workflow

AI access is not a binary question. The better question is which people and systems should be able to use which workflow, with access to which sources, for which purpose.

Least-privilege access matters. An assistant helping with a customer case should not automatically have access to an entire company drive. Retrieval sources should be scoped to the job, and access should reflect both the user and the task.

Retention is part of privacy

Leaders should be able to explain what is logged, what is retained, where it is stored, who can review it, and how long it remains available.

The goal is not to eliminate evidence. Auditability is important. The goal is to retain the minimum information needed for security, troubleshooting, and accountability.

Make exceptions visible

No policy will anticipate every legitimate use case. Private by design means giving exceptions an explicit route: documented risk review, time-bounded approval, named ownership, and a decision about what changes when the exception expires.

Invisible exceptions are where governance quietly fails. Visible exceptions are how a program learns.

A practical test

For any important AI workflow, leaders should quickly answer five questions:

  • What data is permitted?
  • Who can use it?
  • Which systems can it connect to?
  • What is retained after use?
  • How is unusual or high-risk use reviewed?

If the answers are vague, the workflow is not private by design yet. Its privacy posture depends on individual behavior rather than reliable controls.

The bottom line

Private AI is not one deployment choice or a marketing label. It is the result of disciplined boundaries. Companies that build those boundaries into their workflows can adopt AI widely without treating every new use case as a leap of faith.