Resources · For security leaders

A CISO's guide to on-premises AI

You've been asked to approve an AI deployment — or more likely, you've discovered your organization already uses AI you never approved. This guide covers what a security leader should demand from any on-premises AI system, and how to evaluate vendors against those demands.

Start from the real threat model

The most common enterprise AI incident isn't an exotic model attack. It's an employee pasting a customer record, a config file, or a ticket dump into a public chatbot — invisible to your controls and irreversible once sent. Banning AI doesn't stop this; it removes your visibility while usage continues. The realistic strategy is a sanctioned alternative that is both more useful and fully governed.

Eight questions to ask any private AI vendor

QuestionThe answer to insist on
Where does inference run?Entirely on infrastructure you control, with no code path to an external model API
What leaves the network?Nothing by default; anything else sanitized, human-approved, signed, and logged
What stops secrets entering the AI?Deterministic detection that blocks documents outright — reviewable rules, not model judgement
Who can make the AI know something?A two-person approval workflow with separated roles
Can knowledge be scoped by team?Role partitioning enforced at retrieval, not in prompts
What happens when it doesn't know?A refusal with an escalation path — never a confident guess on high-risk topics
Can you stop it instantly?A global kill switch covering every AI function
What do we show the regulator?A tamper-evident audit trail exportable and verifiable offline, without vendor involvement

The evidence standard

Logs are not evidence — logs can be edited. The standard worth demanding is a hash-chained, append-only record where each entry cryptographically covers its predecessor, exported under a digital signature your auditors can verify with public tooling. If a vendor's answer to "prove nothing was altered" involves trusting the vendor, keep looking.

Updates are the overlooked attack surface

A local AI that never updates goes stale; one that updates over a live cloud bridge reintroduces the exposure you eliminated. The pattern to require is the one critical infrastructure already trusts for software: signed offline update artifacts — signature verified against keys pinned on your appliance, content scanned, self-tested, and activated by a human with a rollback path.

What approval should look like

A defensible AI approval ties every claim to a control you watched work: a credential blocked at ingestion in front of your team, a kill-switch drill on the record, a rollback with impact analysis, and an evidence export verified on a laptop with no network. A 90-day pilot structured around producing exactly those artifacts turns an AI decision from a leap of faith into a reviewable engineering exercise.

See it running on your own infrastructure.

The Locs 90-day pilot is fixed-price, fixed-scope, and ends with audit-ready evidence — 100% of the fee credits against installation.

EXPLORE THE 90-DAY PILOT