Your AI assistant probably knows more about your business than you think. Here's why that should concern you.
Case Notes · 2026-05-20
Most businesses using AI haven't read the terms. For sensitive commercial information, that gap is a real risk. Here's what I built instead.
Your AI assistant probably knows more about your business than you think. Here's why that should concern you.
When you type something into ChatGPT, Claude, or any of the popular AI tools — a client name, a price, a strategy you're working through — where does that go?
The honest answer is: further than most people realise, under terms most people haven't read.
For a lot of everyday use, that's probably fine. But there's a category of information that businesses genuinely cannot afford to have floating around on someone else's servers. Anything commercially sensitive that, if it ended up in the wrong place, would be a serious problem.
I recently built an AI assistant specifically designed for that kind of information. This is what I learned.
The problem with standard AI tools
Every time you use a mainstream AI product, your conversation is processed on servers run by that company — typically offshore. Most of them have policies saying they won't use your data for training, but a policy isn't the same as a guarantee that's been reviewed and signed off for your specific situation.
For a business handling sensitive commercial information, that gap matters.
The other issue is that these tools are general purpose. They're built to answer anything, for anyone. What businesses often actually need is something more specific — an assistant that knows their documents, their pricing, their way of doing things — and nothing else.
That's what I set out to build.
What CapOne actually is
CapOne is a private AI assistant that lives entirely inside a client's own platform. You chat with it like you would any AI tool — type a question, get an answer. But everything about how it works under the hood is different.
The simplest way to think about it: it draws only on the business's own approved internal information, inside a private environment, and answers questions from there. Nothing else informs its responses.
It doesn't guess. If it doesn't have a clear answer from the approved material, it says so rather than filling in the gap.
Where the data actually lives
This is the part I think matters most for businesses with sensitive information, so I'll be plain about it.
Everything in CapOne runs on Australian-hosted infrastructure. The information stays onshore, inside an environment chosen specifically because its terms around training, retention, and third-party access stand up to scrutiny. That's a very different posture to using a general consumer AI product and hoping the defaults are good enough.
What it feels like to use
The experience is just a chat window. You type a question in plain English and get a plain English answer.
"What's our standard approach for this type of engagement?" — answered instantly from the business's own material.
"What position have we taken on this kind of question before?" — answered from internal knowledge, not from guesswork.
The people using it don't need to know anything about how it works underneath. It behaves like a very well-informed assistant that only ever speaks from the business's own approved knowledge.
Why this is going to matter more, not less
Most Australian businesses are still in the early stages of figuring out where AI fits for them. The tools are getting better fast, and the temptation is to just start using whatever's available and figure out the data questions later.
That's a reasonable approach for a lot of things. It's a riskier approach for anything commercially sensitive.
The question regulators and clients are starting to ask — "where does your AI process our information?" — is only going to get more common. The businesses that can answer it clearly and precisely are going to have an advantage over the ones that can't.
Building something like CapOne isn't as complicated or expensive as it sounds. And it's a very different conversation to have with a client than "we use ChatGPT."
If you've got information that matters and you're not sure how to think about AI and privacy, that's a good place to start.