On-premise vs cloud AI: the four postures, honestly compared.
If your business handles material you are obliged to protect, the useful question about AI is not "which model is best". It is "which deployment posture do our obligations permit". This page defines the four postures on the market, compares them honestly, and explains where each one makes sense. It is written to be useful even if you end up choosing a different column to ours.
The four deployment postures
1. Public cloud AI. Consumer tools such as free ChatGPT accounts. Prompts are processed on the provider's servers, and on consumer tiers they can be used to train future models. Fast, capable and free, which is exactly why staff use them quietly. For client work in a regulated practice, this posture is generally indefensible.
2. Enterprise cloud AI. Paid business tiers: ChatGPT Enterprise, Claude for enterprise use, Microsoft Copilot. These are serious products. The reputable providers do not train on your business data by default, hold strong security certifications, and offer admin controls. What does not change is the architecture: every prompt and every document still travels to the provider's infrastructure, and for the major providers that infrastructure and the company behind it sit under foreign jurisdiction.
3. Private cloud and sovereign hosting. Dedicated capacity in an Australian data centre, run by you or a local provider. Data stays onshore, which resolves the offshore transmission question. You still depend on a shared facility, network transit, and a hosting relationship, and you now own a genuine infrastructure project: provisioning, scaling, patching and paying for GPUs whether they are busy or idle.
4. No-egress on-premise. The AI runs on hardware inside your building with no path to the internet. Nothing is transmitted because there is nothing to transmit on. Historically this meant building it yourself; the point of a managed unit like Dominion is getting this posture without the project.
The honest comparison
| Public cloud | Enterprise cloud | Private cloud / sovereign hosting | No-egress on-premise | |
|---|---|---|---|---|
| Model capability | Frontier | Frontier | Your choice of open models | Strong open models, tuned to your business over time |
| Where your data goes | Provider servers, may train models | Provider servers, not used for training by default | Australian data centre | Never leaves your building |
| Jurisdiction | Foreign | Foreign for the major providers | Australian | Your premises, Australian law |
| Cost model | Free or low per user | Per seat, per month | Infrastructure + engineering | Per unit, per month |
| Auditability | Provider policy documents | Provider policy documents and certifications | Contract + facility audits | Point at the unit; your security team can inspect the boundary |
| Failure modes | Data absorbed into models; staff misuse | Policy change, subpoena or breach at the provider; offshore processing findings | Facility or network incident; project overruns | Hardware failure (managed under support); no external failure surface |
Being fair to the cloud column
Enterprise cloud AI is the right answer for many businesses. The frontier models are more capable at open-ended general reasoning than anything you can run locally, the per-seat pricing is easy to start small with, and providers such as OpenAI, Anthropic and Microsoft invest heavily in security. If your obligations permit client material to be processed on offshore infrastructure under contract, enterprise cloud may be all you need.
The reason this page exists: for many Australian professional practices, that "if" fails. Legal professional privilege, health information rules and professional confidentiality obligations turn on where information travels and who can access it, not on whether the provider trains on it. "Not trained on" and "never transmitted" are different promises, and only one of them can be verified by standing in your own server room.
What "no egress" means, precisely
A no-egress unit has no route to the internet for your data. Your team connects over your local network; documents are indexed and queried on the unit; the model runs on the unit. Support and updates for Dominion happen through sessions you initiate and supervise, and health monitoring watches the hardware, never your files. The security claim is structural rather than contractual, which is why it is the one posture a compliance officer can verify without reading a trust portal.
Where Dominion sits
Dominion is the fourth column as a managed service: an AI unit installed in your office, running models tuned to your business by ErmosIQ, with monitoring, updates and support included. You get the posture without hiring an infrastructure team.
Dominion is priced per unit, per month on a 12-month term, sized to your practice: unlimited users, no per-user licences, no usage charges. Exact pricing is confirmed in the scoping consultation.
For the full cost picture including worked per-seat comparisons, see what on-premise AI actually costs.
Common questions
Is enterprise cloud AI safe for client data?
What does no egress actually mean?
Is on-premise AI less capable than ChatGPT or Claude?
What about private cloud or sovereign hosting in Australia?
See Dominion answering from your own documents.
A demonstration takes 30 minutes, uses no client data, and comes with no obligation.
Book a demo