Resources
Private AI vs. cloud AI in accounting
When an accounting firm adopts artificial intelligence, the first question is not which model is the cleverest — it is where the model runs, and where the clients' financial data ends up. Everything else follows from those two questions: GDPR compliance, client trust, and the firm's professional responsibility.
Why this is the fundamental question
Every AI service follows the same basic pattern: data travels to a server, a model processes it there, and the result comes back. From the user's point of view that is a single click — but legally and from a security standpoint, everything depends on where that server stands, who operates it, and what happens to the data after processing.
For an accounting firm this is not a theoretical exercise. The firm handles other businesses' financial data every single day — as a data processor, under contractual and statutory obligations. What is a matter of convenience for a private user is a matter of compliance and trust for a firm.
What happens when a document lands in a public AI tool?
The temptation is real: public AI chat tools read invoices impressively well and summarise a bank statement in seconds. But when an accountant pastes a client's document into a public AI tool, several things happen at once:
- The data moves to external infrastructure. Public AI services typically run in a global cloud, often on servers outside the European Union — the data's route and storage location are invisible to the user.
- Retention terms are unclear. How long submitted content is kept — and whether it may be used, for instance, to improve the models — depends on the terms of service. The firm can usually neither verify nor evidence any of it.
- The processing chain is not settled. Under GDPR the firm processes its clients' data; passing that data to an AI provider requires a proper legal framework — a data processing agreement and adequate safeguards. With a public tool, that framework typically does not exist for this purpose.
- Professional confidentiality is at stake too. Clients did not hand over their financial records so that they could end up with an unknown third party.
It is worth being precise here: none of this means public AI is bad technology. It means it is the wrong place for confidential client data.
What private AI means
Private AI delivers the same capability — reading documents, extracting data, making suggestions — inside a closed, controlled environment. In practice it means three things:
- The models run on dedicated hardware — either on EU infrastructure operated specifically for this purpose, or on the firm's own server.
- There is no external AI API. Processing never calls out to a public AI service; the data never leaves the controlled environment.
- Operation is documented and accountable. A data processing agreement (DPA), an audit trail and data export come with it.
The difference, in other words, is not how "smart" the artificial intelligence is — it is the legal and operational frame the technology works in.
A fair comparison
There are honest arguments for public cloud AI: it is cheap or free, instantly available, and excellent for non-confidential work — general text, public information, drafts. An accounting firm's core work is not that kind of task, though: it deals in clients' financial records, for which the firm carries professional and legal responsibility. Here, guarantees outweigh convenience: a written DPA, a searchable audit trail, the ability to export the data, and knowing exactly where the system runs.
| Criterion | Public cloud AI | Private AI |
|---|---|---|
| Where does the model run? | On the provider's global cloud infrastructure, in a location the user cannot see. | On dedicated EU hardware — or on the firm's own server. |
| Where does the data go? | To an external provider, often outside the EU; how long it is kept depends on the terms. | It never leaves the controlled environment; there is no external AI API call. |
| GDPR status | The processing chain is typically not settled for this purpose; guarantees are hard to evidence. | Data processing agreement (DPA), audit trail, data export — documented processing. |
| Control | The provider sets the terms and can change them unilaterally. | The firm knows the terms, fixes them in contract and can verify them. |
How Kontír AI puts this into practice
Kontír AI was designed as private AI from the start. Its own AI model extracts the data from documents — invoices, receipts, bank statements — without calling any external AI service, and the financial data never leaves the country. Firms choose between two editions:
- Kontír AI Cloud: ATAILA hosts and operates it on its own EU infrastructure — a subscription, with no upfront investment and no IT burden.
- Kontír AI Enterprise: the entire system — AI models included — runs on the firm's own hardware; full data sovereignty.
Both editions come with a data processing agreement, an audit trail and data export, and both follow the Kontír AI principle: the system suggests, the accountant reviews and approves — control and responsibility stay with the firm.
Security & GDPR in detail → Compare the two editions → What is an AI accountant? →
Questions about private AI?
In a demo we will show you how Kontír AI does its work while client data stays under your firm's control the whole way.