What on-premises actually does — and what it doesn't.
This page is deliberately conservative. The whole proposition only works if every claim on it survives being read by your lawyer.
On-premises AI is not the only lawful option. It is the option that removes the largest number of compliance obligations, disclosures, third-party dependencies and residual foreign-law exposures at once — and for some regulated workloads it is the only one a professional can comfortably defend.
A great deal of AI marketing implies that sending data across the border is unlawful. It is not, and a buyer who acts on that advice is being badly served. What is true is narrower, and stronger: for specific obligations, specific professional duties, and specific files, keeping the work in your building removes exposure that no contract can remove.
How the architecture backs the claim.
- It physically runs in your building
- The model weights, the documents and the conversations sit on a machine you own, on your network. There is no inference API call leaving the premises. We give you the network diagram and the egress rules, and you can verify it.
- On-premises removes a real Alberta obligation
- Alberta PIPA s.13.1 requires you to notify individuals when personal information is transferred to a service provider outside Canada, and s.6(2) requires your written policies to name those countries. Keeping the workload here removes that obligation rather than merely feeling safer.
- We never train on your data — as a contract term
- Not a policy that can change, and not a setting someone can toggle. It is a covenant in the agreement, alongside confidentiality terms that survive the end of the engagement.
- For Alberta health custodians
- We sign an Information Manager Agreement meeting HIA s.66 and the content requirements of AR 70/2001 s.7.2, and we prepare the documentation you need for the privacy impact assessment s.64 requires before the system goes live.
- Version-pinned models that don't shift underneath you
- Self-hosted open-weight models don't get silently updated by a vendor. The system that passed your acceptance test in March behaves the same way in November — which matters if anyone ever has to validate it.
- Per-user audit trails
- Who asked what, which documents were retrieved, what came back, and when. Retention that you set. The evidence you need if a regulator or a client ever asks how the system was used.
Which rules apply to you.
Current as of 29 July 2026 and reviewed quarterly. This is general information, not legal advice.
| Regime | Who it binds | What it means here |
|---|---|---|
| Alberta PIPA | Most Alberta private-sector organisations | s.13.1 requires notifying individuals when personal information goes to a service provider outside Canada; s.6(2) requires your written policies to name those countries. Keeping the workload on-premises removes both obligations. |
| Health Information Act | Physicians, dentists, pharmacies, physiotherapists, chiropractors, optometrists and other custodians | s.66 requires an Information Manager Agreement with the content set by AR 70/2001 s.7.2 before a vendor may handle health information. s.64 requires a privacy impact assessment submitted to the Commissioner before the system goes live. |
| Law Society of Alberta | Alberta lawyers and their firms | Confidentiality under the Code of Conduct is the binding duty, and it survives the retainer indefinitely. The Law Society's February 2026 generative AI guidance addresses internal and proprietary AI platforms as a way to meet it. |
| OSFI B-10 / B-13 / E-23 | Federally regulated financial institutions and their vendors | Third-party risk, technology risk, and — from 1 May 2027 — model risk management that expressly covers AI/ML. A version-pinned self-hosted stack is materially easier to inventory, explain and validate than a hosted model that changes underneath you. |
| Protection of Privacy Act | Alberta public bodies and their suppliers | Replaced the private-sector-facing half of FOIP. Contains express automated-system provisions, and s.60(4)–(5) makes it an offence to disclose in response to a foreign order from a body with no jurisdiction in Alberta. |
| PIPEDA | Federal works, and interprovincial or international transactions | Permits transfers to a service provider for processing, including outside Canada, given comparable protection and transparency. This is why we do not claim offshore processing is unlawful. |
Claims we refuse to make.
Published deliberately. If a vendor tells you any of the following, ask them to put it in the contract and watch what happens.
“We are HIA-compliant”
Compliance under the Health Information Act is the custodian's status. A vendor cannot hold it on your behalf.
“Certified” or “approved by the Commissioner”
The Office of the Information and Privacy Commissioner reviews and comments. It does not certify, approve or accredit AI systems.
“Compliant with Canada's AI law”
There is no Canadian AI statute. The Artificial Intelligence and Data Act died on the Order Paper at prorogation on 6 January 2025 and has not been replaced.
“It's illegal to store Canadian data in the US”
False. PIPEDA expressly permits transfers for processing. We will not sell against a premise your own counsel can dismantle in one meeting.
“No hallucinations” or “guaranteed accurate”
Unprovable, and it would convert a known limitation of every language model into a contractual warranty.
Everything on this page is general information, not legal advice. Compliance obligations rest with your organisation, and you should obtain your own advice. Statutory references were verified on 29 July 2026 and are reviewed quarterly; this area of law moved substantially between 2024 and 2026. Nothing here implies endorsement by the Office of the Information and Privacy Commissioner, the Law Society of Alberta, OSFI, or any court.
Bring your hardest question.
The ones worth asking are usually specific: this file, this obligation, this regulator. Those are the conversations we want.