How organisations deploy AI — and where we sit
Most companies think “using AI” means having a ChatGPT or Claude subscription. That is one point on a spectrum. For a regulated operator the real decision is not whether to use AI — it is where each workload should run, and who is accountable when it does. Routine drafting can sit with a public model; a board pack built on confidential financials, or an operational process touching a regulated system, cannot. The same company will, and should, sit at several points on this spectrum at once.
The spectrum, plainly
Read left to right, each step trades convenience for control. The cost of running a model falls and your sovereignty over the data rises — but so does the operational burden you take on.
| Tier | What it is | Control / sovereignty | Data exposure | Best for |
|---|---|---|---|---|
| 0 — Direct vendor | One provider, used directly (claude.ai, or a single lab’s API) | Lowest — fully dependent on one vendor’s pricing, uptime and access policy | Everything goes to one vendor | Individuals, low-sensitivity work, a quick start |
| 1 — Routing service | One interface in front of many models, with automatic failover and cost control | De-risks the vendor, not the network | Still leaves your network | Teams wanting resilience and cost discipline without infrastructure |
| 2 — Managed in-cloud | Commercial or open models run inside your own cloud tenancy (Bedrock, Vertex, Azure) | Data stays in your cloud; easier security sign-off | Stays in your tenancy | Most larger enterprises’ first serious step |
| 3 — Self-hosted | You rent the hardware and run your own serving stack | High — you control the stack | Stays on infrastructure you control | High-volume, cost-sensitive, infrastructure-capable teams |
| 4 — Fully local | Everything on hardware you own; no internet after the model is loaded | Highest — survives outages, vendor shutdowns and export controls | Never leaves the building | Sovereignty-critical and regulated workloads that must keep running |
Two things make this our business, not just a chart
Model routing is the layer, not a rung. At every tier you still choose which model runs which task — a frontier model for judgment and synthesis, a cheaper or specialised one for routine, structured work — and the routing layer makes that call automatically on cost, privacy and capability. Owning that layer for a client is the defensible position: it holds the accumulated judgement of which task goes where, and it lets a client move a workload up or down the spectrum without rebuilding anything. It is the same embedded, hard-to-rip-out ground the rest of this plan describes — applied to the plumbing of how AI actually gets used.
You don’t build the bunker on day one. The right posture is to start convenient and move workloads toward control only as sensitivity demands: begin at Tier 0 or 1, move regulated data into Level 2, and reserve Level 4 for the functions that genuinely must survive disruption. The hybrid pattern — a local or in-tenancy model processes the raw, sensitive material and only a structured summary ever reaches a public frontier model — is not a cost trick. For a client under regulatory load it is a compliance architecture: the evidence that sensitive data never left the perimeter.
Where we sit
This reframes what we sell. Not “we’ll help you use AI” — but “we’ll decide where each of your workloads runs, build it there, and own the routing and sovereignty layer that keeps you in control.” For the regulated scale-ups this venture targets, that is precisely the capability they cannot staff and the frontier labs will not provide: an accountable operator who places the work along this spectrum on their behalf, keeps their data on the right side of the line, and is answerable when a regulator asks. It is the moat in section 7, expressed as architecture — and it directly addresses the model-portability and sovereignty exposure the venture has to manage in its own delivery.
← The model: advisory-native AI, built to operate Why now: the timing window →