A procurement officer has a 300-page tender due on Friday. A public chatbot will summarise it in about four minutes, even though the company’s AI policy forbids using one. The LayerX Enterprise AI and SaaS Data Security Report 2025 shows what usually happens next: 77 percent of employees who use AI tools paste data into them, and 22 percent of those pastes contain personal or payment card data (The Register).
THE CAUSE
Why Policy Alone Does Not Stop The Pasting
Staff paste confidential documents into public chatbots because it turns an afternoon of work into a few minutes, and a written policy does nothing to change that trade. Summarising a long tender, pulling the terms out of a contract or drafting a purchase order from an invoice takes hours by hand. With a language model it takes minutes, and the people doing the work know this.
The behaviour doesn’t stop when the tools are forbidden. It moves somewhere IT cannot see: personal accounts, personal phones, and browser sessions outside the managed proxy. IBM’s 2025 Cost of a Data Breach report found that one in five organisations it studied had a breach involving shadow AI, meaning AI tools used without IT approval. Those breaches added about USD 670,000 to the average breach cost, and 63 percent of breached organisations had no AI governance policy at all (IBM). A governance policy is necessary. But when staff can’t follow the rule and still finish their work on time, they route around it.
The risk is the same in every sector. A law firm’s version is an M&A agreement, a hospital’s is a discharge summary, and a bank’s is a loan file. The trigger each time is a deadline and a tool that meets it.
THE EXPOSURE
What Leaves The Network When A Document Is Pasted
When someone pastes a confidential document into a public chatbot, the full text goes to a third-party processor outside your network. From then on, the provider’s terms and the user’s account type decide what happens to it. Retention periods, whether prompts are used for training, and where the data is stored all vary between consumer and business tiers. None of it can be audited from your side once the text is gone.
For organisations under HIPAA, GDPR or a national data residency law, the transfer can itself be the problem, whatever the provider does with the data afterwards. Samsung restricted staff use of generative AI tools in 2023 after engineers pasted internal source code into a public chatbot, as Bloomberg reported that May. Every sector has its own version of that incident. What varies is whether anyone found out.
Redaction helps less than people expect. Strip the party names from a supply contract and the pricing schedule, the liability caps and the termination clauses are still there. Those clauses are usually the confidential part.
THREE RESPONSES
Three Ways Organisations Respond, And What Each Leaves Open
Organisations usually try one of three things: block the chatbots, filter what goes into them, or give staff an approved tool that runs where the data is allowed to be. Only the third removes the time pressure that drives the behaviour.
Block The Domains
Blocking chatbot domains at the web proxy stops the managed laptop. It does nothing about a phone photo of a printed page, a personal laptop at home, or a new AI service the block list hasn’t caught yet. The tender still has to be summarised, so either the work slows down or it moves out of sight.
Filter And Redact
Data loss prevention tools can inspect prompts and mask names, account numbers and identifiers before anything is sent. They are worth having. The document itself still goes to a third party, though, and commercial terms can’t be masked without making the request useless.
Provide A Local Alternative
Give the people doing the work a tool that is just as fast and runs inside your network. The four-minute summary stays four minutes and the document never crosses the boundary. ARSA Sovereign was built for this case.
THE LOCAL OPTION
What A Local Appliance Changes
A local AI appliance does the same summarising, extraction and drafting on hardware inside your building. The confidential document never has to leave the network for the work to get done. ARSA Sovereign is a 4U rack or tower system that reads scanned PDFs, handwritten annotations and dense multi-page layouts. It runs a 27B-class open-weight vision-language model on its own accelerator and needs no outbound connection at inference time. According to ARSA, no document, query or result is sent to ARSA or to any third party. The vector index and document vault sit on encrypted local storage.
The interface matters as much as the location. Getting a structured purchase order out of a blank chat box can take many prompts, which is one reason people stay with the public tool they already know. On Sovereign, the user states the goal in plain language, such as auditing a vendor contract against standard NDA terms. The system then generates a step-by-step form with the fields, tables and validation that task needs. Each field can be changed later in plain language from a side panel.
Where results need to go into Odoo, SAP or Zoho, the connectors are read-only by default. Every write waits for human approval before it commits, and there is no autonomous write mode to enable. The appliance can run fully air-gapped, with model updates and licence activation delivered as signed offline packages.
Sovereign is currently in pilot. The figures below are the ones ARSA publishes. Anything beyond them, such as throughput on your own document mix, is a question to ask ARSA directly.
SPECIFICATION
The Two Sovereign Configurations Compared
The two configurations run the same operating system and workflows. They differ in model precision, document throughput and how much context each can hold at once.
| ARSA Sovereign 48 | ARSA Sovereign 96 | |
|---|---|---|
| List price, perpetual | $26,900 | $44,900 |
| AI accelerator memory | Single 48 GB | 96 GB primary, plus a dedicated 24 GB for OCR |
| Language model precision | Quantised | Unquantised, full precision |
| Document OCR | Shares the accelerator | Runs on its own accelerator |
| System memory | 128 GB ECC | 128 GB ECC |
| Storage | 8 TB enterprise | 20 TB enterprise, RAID 1 |
| Support, updates, fleet management | Three years included | Three years included |
| Support from year four | $4,500 per year | $7,500 per year |
| Lead time | Three to four weeks | Three to four weeks |
Prices are international list prices in USD. They exclude import duty, VAT, customs clearance and rack installation, and the exact configuration is quoted. There is also a monthly option starting at $1,090. Systems ship from Surabaya.
THE LIMITS
What It Will Not Do For You
A local appliance removes the reason to paste. On its own, it cannot stop someone who still decides to. You still need the policy and the proxy rules. The difference is that the policy becomes one people can follow and still get their work done.
The model has limits that should be stated clearly before a pilot begins. ARSA’s own documentation says a 27B-class open-weight model is not equivalent to a frontier-scale hosted model on the hardest reasoning tasks. It is built for document extraction, structured summarisation, form generation and ERP workflows. If your team’s real need is maximum raw capability and your data is allowed to leave the building, a cloud service is the better answer. The same applies to occasional, bursty workloads, where the cloud is cheaper. The appliance also needs rack space or office floor space, a power budget, and someone willing to own on-premise hardware.
If you aren’t sure the workload justifies an appliance, start with a paid feasibility assessment from ARSA’s services. It costs $4,500, takes two weeks, and the fee is deducted from the project fee if you contract within 90 days.
FAQ
Questions Engineers And Compliance Teams Ask
Is It Safe To Paste Confidential Documents Into A Public AI Chatbot?
For contracts, patient records and financial statements, generally no. The full text leaves your network for a processor you don’t control and can’t audit. Business tiers may offer better retention terms than consumer accounts. But under data residency or health privacy rules, the transfer itself may already be the breach.
What Is The Difference Between A Private LLM And A Public LLM?
A private LLM runs on infrastructure you control, so prompts and documents stay inside your network. A public LLM runs on a provider’s servers and receives everything you type. The trade-off is capability against control. Public services usually offer larger models, while a private deployment keeps the data where your regulators expect it to be.
Will Banning Public Chatbots Stop Data Leakage?
Not reliably. A ban blocks managed devices, but the time saving that drives the behaviour is still there, so the pasting moves to personal devices and accounts. Bans work best alongside an approved tool that does the same job inside the network.
Can ARSA Sovereign Run Without Any Internet Connection?
Yes. Inference needs no outbound connection. Model updates and licence activation come as signed offline packages that you transfer through your own approved media process. The encrypted fleet management channel can be switched off entirely.
Does ARSA See The Documents Processed On The Appliance?
No. Text extraction, embedding, indexing and reasoning all happen on the appliance, on encrypted local storage. ARSA states that nothing is sent to ARSA or to any third party.
How Capable Is A Local Model Compared With A Public Chatbot?
On the hardest reasoning tasks, it is less capable than the largest hosted models. On document extraction, structured summaries and form-driven workflows, it is built to do the job. The practical test is whether it handles your own documents, and a pilot is the place to measure that.
NEXT STEP
Give Your Team A Tool They Are Allowed To Use
The pasting stops when the approved tool is as fast as the forbidden one. See the configurations, the security platform and the ERP connectors on the ARSA Sovereign product page, or contact ARSA to discuss a pilot on your own documents.
Sources:
– The Register: Employees regularly paste company secrets into ChatGPT
– IBM: 2025 Cost of a Data Breach Report


