Resources
A retrieval system returns prose that has already been assembled, so by the time an answer exists any disclosure has happened. What has to be true at each stage of the pipeline.
Retrieval supplies knowledge; fine tuning shapes behavior. Most enterprise requirements are knowledge problems, and reaching for fine tuning there is the expensive mistake.
Private LLM describes at least five different arrangements with different guarantees. Five direct questions distinguish them without anyone having to agree on the terminology.
Most models described as open source are open weights, which is a different and weaker claim. What the terms mean, why it matters commercially, and how to check rather than assume.
Organizations expect this decision to be about performance. For most enterprise workloads it is about permissions, lifecycle and where the data sits.
Generative AI arrives whether or not anyone approves it, so the useful question is rarely whether to allow it but how to make the approved path better than the unapproved one.
An AI system is a new set of paths in and out of your information. Several of them do not look like data transfers to the people using them, which is most of the problem.
An AI system must not become a way around the authorization model you already have. That is violated routinely, and usually not by anyone deciding to violate it.
An AI environment is a set of APIs, and most of what goes wrong there is not novel. It is the ordinary API failure set arriving where teams are thinking about models.
Every argument for logging an AI system is an argument for collecting the most sensitive material in the organization into one searchable place. Both halves are true.