Neither is automatically safer. On-device AI keeps data off other companies' servers, which suits the most sensitive material, but it moves the security burden to your own laptops and phones: theft, backups and updates become your problem. For everyday work, a business-plan cloud tool with training off by default and admin controls is usually the safer choice.
The deciding factor is what could go wrong with a specific kind of data. A lost laptop holding months of screen snapshots is a different risk from a vendor keeping a prompt for 30 days in a safety log. And many "on-device" features hand harder requests to a cloud anyway; Apple's Private Cloud Compute does exactly that, by design.
What on-device and cloud actually mean now
The labels get used loosely, so it's worth pinning them down:
- Cloud AI means the model runs on the vendor's servers: ChatGPT, Claude, Microsoft 365 Copilot, Gemini in Workspace. Your prompt travels there, gets processed and usually gets stored as history, with copies in safety logs for a period.
- On-device AI means the model runs on your own hardware. On Windows, Copilot+ PCs use a chip called an NPU (Microsoft requires one rated at 40 trillion operations per second or more) for features such as Recall, Click to Do and live captions. On Apple devices, many Apple Intelligence features run entirely on the phone or Mac. And you can install open-weight models on your own computers, which is covered in whether a small business can run AI on its own computers.
- Hybrid is increasingly the norm. Apple says that in many cases its models run on the device, and more complex requests go to Private Cloud Compute, larger models on Apple's own servers.
So the useful question isn't "cloud or device?" in the abstract. It's "for this piece of data, where does it go, who else could see it, and what happens if the device or the vendor has a bad day?"
Where each kind of risk sits
This comparison assumes a business plan for cloud tools and ordinary company laptops and phones for on-device use.
| Risk | Cloud AI (business plan) | On-device AI |
|---|---|---|
| Data leaving your control | Yes, by design, under the vendor's contract | No, for features that genuinely stay local |
| Used for training | Not by default on business plans | Not applicable for local processing |
| Retention | Vendor's schedule plus your settings | Whatever your device keeps, until you delete it |
| Lost or stolen device | Sign the session out remotely; data stays in the account | Whatever is on the device goes with it, protected only by its encryption and sign-in |
| Breach at the provider | Possible; the vendor's security team defends it | Not applicable; your own device security is the defence |
| Backups | Handled by the vendor | Your responsibility |
| Admin visibility | Admin consoles, audit logs, retention policies | Little, unless devices are centrally managed |
| Accuracy | Larger models, generally fewer errors | Smaller models, more checking needed |
Two rows surprise people. First, accuracy is a safety issue: a smaller local model that misreads a contract or miscalculates a quote creates risk of its own. Second, admin visibility cuts the other way from what you'd expect. On a business cloud plan, the owner can see accounts, set retention and remove a leaver in a minute. On a dozen unmanaged laptops, nobody can see what local AI tools are keeping.
Recall: what an on-device feature can quietly collect
Microsoft's Recall is the clearest example of on-device AI's trade-off. It takes periodic snapshots of your screen and lets you search them in plain language: "the quote I was looking at last Tuesday". Microsoft's documentation is emphatic about privacy, and much of it is reassuring:
- Snapshots are stored and analysed locally, aren't sent to Microsoft, and no internet connection is used to save or analyse them. IT admins can't view them and neither can Microsoft.
- Recall is opt-in: users must consent before any snapshots are saved, and admins can't switch saving on for them.
- Opening Recall needs Windows Hello with a fingerprint or face sign-in, and the snapshot database is encrypted, with keys protected by the device's security chip.
- A sensitive information filter is on by default and skips saving a snapshot when it detects potentially sensitive information, working entirely on the device.
- On managed business devices Recall is disabled and removed by default until an admin allows it.
Now the small-business reality. Many small firms run ordinary Windows laptops that nobody manages centrally. Microsoft notes that on unmanaged Copilot+ PCs, Recall is available by default, though each user still has to opt in. The policies that cap how long snapshots are kept (30, 60, 90 or 180 days) and filter specific apps and websites through central management apply only to the Enterprise and Education editions of Windows. Individual users can still add apps and sites to Recall's filters in its own settings, but someone has to think of it.
Suppose an HVAC installer's office manager (an illustrative case) opts in because searching old quotes sounds useful. Over three months the laptop builds a searchable timeline of everything she saw: customer addresses, engineers' notes about access codes, supplier price lists and her own banking. It's encrypted and never leaves the laptop, which is genuinely better than sending it anywhere. But if that laptop is lost with a weak PIN, or shared with a colleague who signs in as her, the timeline is the most complete record of the business anywhere. The sensible settings: leave Recall off on shared office PCs; where someone wants it, filter the banking site, the job-management system and the password manager, and use Windows Hello with a fingerprint rather than a guessable PIN. Whether a Copilot+ PC is worth buying at all is weighed up in whether you need a Copilot+ PC or AI laptop.
Apple's hybrid: device first, Private Cloud Compute second
Apple's design shows what careful hybrid looks like. Its support pages say many Apple Intelligence tasks run entirely on the device, and requests that need more computing power go to Private Cloud Compute, where the data "is not stored or made accessible to Apple", is used only to fulfil the request and isn't retained, and where independent researchers can inspect the server software to check the promise. You can even see what went to the cloud: Settings, then Privacy & Security, then Apple Intelligence Report produces a file listing requests sent to Private Cloud Compute over the last 15 minutes or 7 days.
The weak point for business use is the optional ChatGPT extension. Apple says you're asked before any information is shared with ChatGPT. Used without signing in to a ChatGPT account, OpenAI must process the request only to fulfil it and mustn't store it or use it for training. Signed in to a personal ChatGPT account, OpenAI's own policies apply, which means your consumer account's history and training settings. An illustrative cleaning company owner using Writing Tools on her iPhone to tidy client emails is on the safe side of that line; the same owner tapping "use ChatGPT" while signed in to a personal Plus account has moved client details into a consumer account. The business angle on Apple's features is covered in Apple Intelligence for business owners.
A locksmith sorts its data into three piles
Consider how an illustrative three-person locksmith, with about 1,200 customer records and roughly 35 jobs a week, approached it. Rather than choosing cloud or device wholesale, the owner sorted the firm's information by what could go wrong with it:
- Never goes into AI, cloud or local: key codes, master-key system details, alarm codes, and "house empty until" notes. About one job in five carries details like these, around 7 a week or 360 a year. They stay in the job management system only.
- Business-plan cloud AI: customer emails, quotes, invoices, review replies and supplier comparisons, with names where needed. The firm uses ChatGPT Business, which has a two-seat minimum, so two Standard seats at $25 a month each billed monthly: $50 a month. Business data isn't used for training by default, and the owner can remove a leaver in a minute.
- On-device is fine, and convenient: quick rewrites of texts and emails on phones with Apple's Writing Tools, and live captions on calls. Nothing sensitive is typed into either that wouldn't already be in a text message.
The interesting result is what the firm didn't do. It didn't buy new hardware to run a local model for pile 1, because the right answer for key codes was "no AI at all", not "private AI". Local models make sense when you need AI's help with sensitive material, such as summarising a confidential document, and that wasn't this business's problem. The decision took an afternoon and cost $50 a month. Where each cloud tool keeps what you put in is mapped in where your data is stored when you use AI tools.
When on-device is the safer call
Keeping AI processing local earns its place in a few specific situations:
- A contract forbids third-party processing. Some commercial clients' terms rule out sending their information to any subprocessor. A local model on a well-secured machine may be the only way to use AI on that client's documents at all.
- The material is highly sensitive and needs AI help. Summarising a solicitor's letter about a dispute, or drafting a response to an insurer's investigation, are jobs where "no copy anywhere else" is worth a less capable model.
- You work where connections are poor. A roofing contractor dictating survey notes on a roof with no signal gets transcription on-device or not at all.
- You can't use a business plan. A sole trader on a tight budget who would otherwise paste client details into a free consumer chat tool is safer using on-device features for that work.
When the cloud is the safer call
For most small-business work, a business-plan cloud tool is the lower-risk option, for reasons that have nothing to do with where the chips are:
- Lost devices. An illustrative removals firm had a laptop stolen from a van. Its cloud AI accounts were signed out remotely within minutes and nothing was lost, because the history lived in the account, not the machine. Had the same laptop held a local model's chat history and a folder of customer documents, the protection would have come down to its disk encryption and sign-in.
- People leaving. Removing someone from a business workspace takes a minute. Getting data off their laptop after they've gone can be impossible.
- Backups and continuity. The vendor backs up the service. Local data is only as safe as your own backup routine.
- Accuracy. Larger models make fewer mistakes on the complicated jobs, and a wrong answer to a customer is a risk in itself.
Cloud safety depends on the plan, though. The same data in a free consumer account, with training switched on and no admin, is a different proposition. If your team is still using personal logins, sort that first; it matters more than the cloud-versus-device question.
Five questions to ask of any new AI feature
New AI features arrive in apps you already use every few weeks, and most don't say clearly where they run. Five questions sort them quickly:
- Where does the processing happen? Check the vendor's help page for "on-device", "on your device" or a named cloud service. If it doesn't say, assume the cloud.
- What's kept afterwards, and where? A local feature that keeps a searchable history on the device is a different risk from one that forgets everything.
- Which account is it tied to? Business account, personal account or none. This decides whose terms apply.
- What happens if this device is lost tomorrow? If the answer is "a stranger could read our customer list", the device settings matter more than the AI.
- Would a mistake here matter? If yes, the more capable model, usually the cloud one, may be the safer choice.
An illustrative landscaper tested a new phone app feature that turns photos of a garden into written site notes. Answers: processing happens in the app maker's cloud; photos and notes are kept in the app's account indefinitely; it's tied to the landscaper's personal login; a lost phone would expose nothing extra because the phone is encrypted; and mistakes in site notes are caught at the quoting stage anyway. The verdict was to use it, but to move it to a business login and set a reminder to delete old surveys each quarter. Five minutes of questions turned a vague worry into two specific settings.
Settings that make either option safer
Whichever way each job goes, a handful of settings do most of the protecting:
- Cloud: use business plans (no training on business content by default); turn off model training on any personal plan that touches work; set retention where the plan allows; require two-factor sign-in; keep a list of which tools hold which data.
- Devices: full-disk encryption on every laptop (BitLocker or Device Encryption on Windows, FileVault on a Mac); fingerprint or face sign-in rather than short PINs; automatic updates; a tested backup; and the ability to lock or wipe a lost device remotely.
- On-device AI features: Recall off on shared PCs and filtered where used; Apple Intelligence reports checked occasionally if you want to see what went to the cloud; ChatGPT extensions used signed out, or signed in only to a business account.
The short version: put each kind of data where its worst day is least bad. For most of what a small business does, that's a well-configured business cloud plan. For the handful of things that should never leave the building, the safest AI is often none at all, and where you do need help with them, a local tool on a properly secured machine.
Further reads
- Open-Source vs Paid AI Models: What Small Businesses Should Know — The model choice behind running AI on your own machines.
- Is Open-Source AI Really Free? The True Cost for a Small Business — What local, open-source AI really costs once you count time.
- Is DeepSeek Safe to Use With Business Data? — A worked safety check on one specific cloud AI.
- What Is Data Loss Prevention, and Does a Small Business Need It? — Tools that stop sensitive data leaving, cloud or local.
- Business Data Backup Checklist Before You Connect AI Tools — Backups matter more once data lives on your own devices.
- Does Microsoft 365 Copilot Keep Your Business Data Private? — How Copilot's cloud handles business data.
- n8n Self-Hosted vs Cloud: Real Costs for a Small Business — Both price lists side by side, the upkeep hours self-hosting really takes, and a roofing contractor's year costed both ways.
- Zero Data Retention: What It Means When You Choose an AI Tool — What a zero data retention promise really deletes, the exceptions OpenAI, Anthropic and Google keep, and the vendor questions that expose weak claims.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Microsoft Learn (Manage Recall for Windows clients; Data, Privacy, and Security for Microsoft Copilot); Microsoft Windows pages on Copilot+ PC requirements; Apple Support (Apple Intelligence and privacy; Turn on ChatGPT) and Apple's ChatGPT extension privacy page; vendor privacy defaults and prices from pages checked September 2026.