Wrivio
Get Wrivio
6 min readBy Wrivio Team

Which Writing Tasks Should Stay on Your Own Machine

Most AI policies ask people to assess whether their text is sensitive before deciding where to process it. That instruction fails, reliably, and the reason is worth understanding: it requires a judgment call at the moment when the person has the least capacity to make one.

It is 18:30. The message needs to go tonight. The tool that works is one tab away. Nobody performs a data classification exercise in that state.

The fix is categories rather than judgment. Here is a list you can apply without thinking.

Always Local

Anything with a client or customer name attached to a matter. Not the name alone, but the name connected to what you are doing for them. That combination is the confidential part.

Financial figures tied to an identifiable party. Revenue, pricing, a settlement number, a valuation, salary.

Personnel matters. Performance issues, disciplinary processes, restructuring, complaints, anything about a named individual’s employment. This category also carries the heaviest regulatory weight.

Contract and negotiation language. Terms, positions, the concession you are willing to make and the one you are not.

Health information. Any of it, about anyone, without exception. This is a special category under GDPR and separately regulated in most other jurisdictions.

Legal advice and anything privileged. Privilege is a fragile thing and transmitting the content to a third party is not the way to test how fragile.

Credentials, keys, and configuration. These should not be in a message at all, and if they are, they certainly should not be transmitted for a rewrite.

Anything a client asked you to keep confidential. They asked, so the question is settled.

Anything on untrusted network infrastructure. Hotel wifi, conference wifi, an airport. A local model works offline, which removes the question.

Cloud Is Fine

Generic drafting with no identifying detail. A template, a policy in the abstract, a blog post about your industry.

Public-facing content. It is going public, so transmitting it changes nothing.

Long-form generation from a non-identifying brief. This is where frontier models earn their price, and it is safe when the brief carries no specifics.

Learning and exploration. How to phrase something in general, what a term means, how a document is usually structured.

Why Categories Beat Judgment

Three reasons, and the third is the important one.

They are answerable instantly. “Does this contain a client name attached to a matter” takes no deliberation. “Is this sensitive” invites a debate with yourself that you will resolve in favor of convenience.

They are auditable. A category list produces a defensible position. If asked how you decided, “personnel matters always stay local” is an answer; “I judged it not to be sensitive” is not.

They fail safe. When someone is unsure, the instruction is to use local, which is never wrong. Ambiguity resolves toward the safe option instead of toward the fast one.

That last property is what makes this work in practice, and it depends on local being genuinely fast. If the private option is slower or worse, people will find reasons their text is not in a category. A tool that responds in two seconds behind a hotkey does not create that pressure. See shadow AI statistics for 2026 for what happens when it does.

The Rule That Covers The Gaps

No category list is complete, so add a catch-all that people can actually apply:

If you would hesitate to paste it into a browser on a shared screen, it stays local.

That test works because it converts an abstract privacy question into a concrete social one, and people are good at the social version. It also catches things a category list misses, which is the point of having it.

Why Local Is Categorically Different

Worth being precise about what the local option actually buys, because “it is more private” is too vague to be useful.

Every AI vendor has a privacy page, and most of the commitments on it are true. They are also policies: made by companies, revised by companies, subject to acquisitions, commercial pressure, and lawful process.

A model running on your machine is a different kind of thing. There is no request to log, no retention window to configure, no subprocessor chain to audit, and no jurisdiction question to answer, because no transmission occurred. You can verify it by disconnecting the network and watching the rewrite still work.

For the always-local categories above, that difference is frequently not a preference but an obligation. There is more in why open weights matter for workplace privacy.

Writing It Down For A Team

The version that goes in a policy document, phrased so it can be followed.

Before:

Employees should not process confidential or sensitive information using external AI services and should exercise appropriate judgment regarding data classification.

After:

Use the local tool on your workstation for anything involving a client name attached to a matter, financial figures for an identifiable party, personnel matters, contract or negotiation language, health information, or anything a client asked us to keep confidential. It runs on your machine and sends nothing externally, so no approval is needed and you do not need to assess sensitivity. If you are unsure, use it; it is never the wrong choice. For general drafting with no identifying detail, the approved cloud tool is fine.

A Wrivio Context for policy writing could say:

Rewrite this as a workplace policy for a general professional audience. Clear and direct, complete sentences, no contractions. Use concrete categories rather than abstract terms like sensitive or appropriate. Keep every category, rule, and exception exactly as written. Do not add approval steps that are not in the original, and do not replace specific instructions with general principles.

Press Ctrl+Shift+Space and read the diff. Concrete categories collapsing back into “exercise judgment” is the failure mode, and it undoes the entire document. There is a fuller template in how to write an AI use policy for a small team.

Common Questions

Is a client’s name alone confidential?

Usually less so than the name connected to what you are doing for them. The combination is what matters, and since most messages contain the combination, treating the name as a trigger is the simpler rule.

What about anonymizing text instead of processing locally?

Legitimate and genuinely useful for cases where you need frontier capability. It requires care, because partial anonymization frequently leaves enough context to identify the party, and it takes time you may not have.

Does an enterprise AI agreement move things out of the always-local list?

It can, for some categories, and that is a decision for whoever owns your risk register rather than for an individual. Health information and privileged material are the two I would leave local regardless.

What if my employer has no policy?

Use the list above. If someone later asks how you decided, you have a defensible answer, which is more than most people in your position will have.

Download Wrivio for Windows to make the local option the fast one, so the categories are easy to follow.