On-prem AI is a hardware answer to a policy question
An estate-bar fight over where client documents go is the budget decision every RIA principal is about to make, and the box is the smallest part of it.
At some point this week, an estate-planning attorney will paste a client's trust instrument into a free AI chatbot and ask for a summary, and the summary will be good: seconds to produce, mostly accurate, an hour of reading saved. Craig R. Hersch, a Florida Bar board-certified wills, trusts and estates attorney and a partner at Sheppard, Brett, Stewart, Hersch, Kinsey & Hill, and a co-author open their Sept. 23 WealthManagement.com piece with that scene and with the observation that it may occur to no one until much later where the instrument went, whose servers now hold it, and what those servers will do with it.
The authors' point is that both halves of that moment are true at once: the tools earn their keep and the confidentiality exposure is real, and it is the tension between the two that keeps 'on-premises AI' turning up in bar journals and practice-management conversations. That recurrence is why the article sets out to explain the difference between running a model on hardware the firm controls and sending the work off site, though the available text stops mid-definition, so whatever the authors propose for cost, staffing, or vendor selection does not appear.
For an RIA principal this reads less like a warning about chatbots than a budget line arriving early. The document in the example belongs to the estate bar, but the exposure does not: a wealth firm's vault holds the same class of paper, and the question the trusts-and-estates crowd is arguing over is the one an advisory firm answers every time it signs a software contract—what leaves the building, who holds it, on what terms. The estate bar is having that argument in public, in bar journals rather than in procurement reviews.
Whether the model runs on the firm's own rack or on a vendor's machines is a governance question wearing a hardware costume, and the deployment choice gets the meeting because it comes with an invoice while retention, access, the audit trail, and the rule about what staff may do in a browser tab arrive, if they arrive at all, as policy.
The instrument has already left the building
The paste already happened, and that is the part of the anecdote with teeth: the exposure the authors describe begins before any deployment decision is made, in a browser tab nobody asked about. An on-premises model does not undo that visit; it gives sanctioned work somewhere better to land, which is a real benefit and a narrow one, and the ground it covers is the inference path—where the client's text goes to a model the firm owns rather than to a vendor's endpoint.
Everything past that is policy—how long outputs are kept, who can search them, whether they surface in discovery, and what happens when the person who configured the thing leaves. The title's image of an associate working out of a server closet suggests what the in-house version costs besides the purchase: a machine to maintain and someone on staff who understands it, and those are real obligations whose accounting does not appear in the available text.
The judgment worth making is about order of operations: a firm that buys the box and leaves the retention schedule, the audit trail, and the browser-tab rule unattended has spent capital on the least of its problems, buying the visible quarter of a regime that only functions when the invisible three quarters are also in place. On-premises deployment can be the right answer for a firm whose clients ask where their documents physically sit, but that does not make it the first purchase.
Who writes the terms
This publication has argued that the AI premium in wealth management has moved from the model to the governed client record, and that whoever writes the AI data terms keeps the client. The on-premises question is a live test of that position: running models on your own hardware is one way to write the terms, and it is the version most easily explained across a conference table, but the terms themselves are a document—a retention schedule, an access list, a chain of authority—and no rack ships with one.
There is a second-order consequence the estate bar's framing makes visible: if the governable record is the product, the commercially decisive moment is the advisor's confirmation of what the machine produced, which is where a firm's liability and its fees both sit. A firm can automate the drafting and still lose the relationship at the confirmation, and the deployment choice leaves that untouched; the record is what makes the confirmation defensible six months later.
The same logic ran through this week's Meristead news: the portability of the client relationship is what a decade of converting do-it-yourself investors into a $1.4 billion book actually produced, and the rebrand made it explicit. A governed record is what makes that portability hold when a client asks for a copy, a regulator asks for a trail, or an acquirer asks for the book.
Three years from now the model will be different and the chips will be different, and the question the trust instrument raises will be the one still open: who can retrieve it, on whose authority, and how fast. That is something a principal settles with a policy and a signature, and it is the piece the estate bar, having named the bind, is still arguing out loud.