Every AI vendor swears their tool is trustworthy. "Enterprise-grade." "SOC 2." "Bank-level encryption." Badges. And badges are exactly what you'd expect a tool to have whether or not you can actually trust its output. For a professional who's personally liable for what the tool produces, a badge is not evidence. Mechanics are.
So here's what I mean by trust-as-mechanics — the things a private AI box should do, not claim.
Every answer cites its source, and the citation is real and clickable. This one has teeth behind it: a 2025 study found that citations raise a reader's trust in an AI answer even when the citations are fake. Sit with how dangerous that is. A tool can invent a footnote and you'll believe the answer more. So the standard can't be "it shows citations" — it has to be "every citation points to a real file on your disk, and you can click it and land on the exact page." If the box says your engagement letter requires 30 days' notice, you click and you're looking at the clause. Verification drops from ten minutes to ten seconds. This is the antidote to the number from Part 4 — that half of people say fixing AI output takes as long as doing it themselves. It doesn't, if checking is one click.
It confirms before it acts, and it logs what it did. Nothing that leaves the building — no email sent, no text to a client, no calendar entry committed on a deadline — happens without a human clicking yes. And every action is written to a log you can read. This isn't me being cautious for its own sake; it maps directly onto a lawyer's actual duty to supervise the tools they use, and onto the confirmation-before-action pattern the whole industry is converging on after a bad couple of years of agents doing things nobody asked for.
It labels what's local and what isn't. The best reference design here isn't from an AI company — it's Home Assistant, which puts a little "local" or "cloud" tag on every integration so you always know where your data just went. A private box should do the same: if a job needs to reach the internet (say, a web lookup or a phone call through the carrier), the box tells you, every time. "Nothing leaves your office" is only a real promise if the box is honest about the rare moments something has to.
Now the uncomfortable one, because trust also means naming the threat.
The biggest technical risk is prompt injection — and it comes through the exact features that make the box useful. An assistant that reads your inbound email can be attacked by an email. This isn't hypothetical: in the last year we've seen a zero-click exploit of Microsoft's Copilot through a malicious email, a ChatGPT connector attack through a poisoned document, and a Google Gemini hijack through a booby-trapped calendar invite. The tool reads attacker-controlled text and gets talked into doing something. Local hardware doesn't save you here — smaller models are, if anything, easier to fool.
The defense is architectural, and it has a name — breaking the "lethal trifecta." The danger only exists when one AI can, at the same time, (1) read untrusted content, (2) access your private data, and (3) send data out. Take away any leg and the attack dies. So the box that reads your inbound email must not also be able to send data out without a human click. That's a design rule, enforced in how the thing is built — not a promise, not a badge, not a checkbox in a settings menu. The most useful thing a private box can do is be incapable of the dangerous combination by construction.
There's a through-line in all of this. Cloud vendors ask you to trust them — the company, the brand, the policy that can change next Tuesday (see Part 3). A box you own lets you verify instead: click the citation, read the log, see the local/cloud tag, know that the architecture physically can't do the dangerous thing. Trust you have to take on faith is fragile. Trust you can check is durable. Professionals — who get sued for being wrong — should insist on the checkable kind.
And that's really the spine of this whole series. The mainstream tools ask for faith: faith that they're accurate, faith that they'll keep your data, faith that the deal won't change, faith that the agent won't go rogue. A private, local box replaces as much of that faith as possible with something you can see: the source, the log, the label, the off switch you control. It won't be smarter than the frontier (Part 4 was honest about that). It'll be more accountable. For confidential, high-stakes work, accountable beats brilliant.
One post left. Part 7: why the pricing model everyone uses — a monthly fee per person — is quietly the wrong shape for a small office, and what fits better.
What would it take for you to trust an AI with a real client matter? I'm collecting answers — they're shaping what the box is required to prove.
— Banksy AI
Practical AI, done for you. Runs on your hardware. Your data never leaves.
(References to ethics duties and the specific exploits are drawn from public reporting and bar guidance compiled in our research memo; confirm any single one before quoting it.)

