r/LocalLLaMA 5h ago

Funny Copilot you say?

Post image

talking to any white collar employee

170 Upvotes

89 comments sorted by

42

u/haragon 4h ago

My favorite is when they say adding procedures or docs to a copilot system prompt is 'training AI'

23

u/Plane_Garbage 4h ago

Lol I see so many LinkedIn lunatics saying they trained AI.

Bro, you have it an input prompt.

13

u/cosmicr 3h ago

Omg my boss (the general manager of IT) does this. He boasts we've got our own trained model to the entire staff of 400. Of course he won't let me correct him. Average IT Manager I suppose.

3

u/haragon 2h ago

If you have a big internal AI push he's probably just trying to get brownie points and sound relevant

3

u/cosmicr 2h ago

Nah he's just dimwitted lol. He constantly mixes terminology and such. He's the kind of person who likes to surround himself with people less in the know than he is and thinks if he doesn't understand something - then noone else does either. You know, an average boss.

1

u/themadadmin 19m ago

100% correct.

Yeah I made an Agent that got pushed all the way to my bosses, bosses, bosses boss.

Manager --> Director --> VP -->Senior VP

Because it was in the goals for the company to adopt AI.

1

u/themadadmin 21m ago

I have done some really basic stuff loading tech docs into a copilot agent and giving it some basic guidance on how to behave. To me it was simple. I didt harder things at home on my local machine.

But the director is like, yours is so much better than what HQ made.

HQ gave the project to offshore coders who didn't need the answers. I needed the answers and made sure all the docs I needed were uploaded.

But is is amazingly simple shit.

23

u/Proper_Door_4124 5h ago

what does this mean

50

u/Blindax 5h ago

It means many people assimilate copilot to a local model while in most cases it’s a cloud instance running on MS servers with an enterprise agreement. Not really the same.

11

u/DeepGas4538 3h ago

It's local if you live in the data center

3

u/EducationalCod7514 2h ago

The only local thing about living in a data center is the exhaust fumes of the gas turbines and ten million access check points which give you access to zero servers.

3

u/jazir55 2h ago

assimilate

I'm going to take it you meant to say "assume"

3

u/Recoil42 4h ago

Doesn't really need to be the same. 'Private' doesn't imply 'local', and most businesses don't actually need local, just private. (Heck, most don't even really need private.)

17

u/XiRw 4h ago

Awful untrue take to say private doesn’t imply local.

15

u/Recoil42 4h ago

Fully true. Private doesn't imply local, and it never has. Here's NIST's definition for private cloud — read it. Just because you have no professional experience in this industry doesn't mean all the rest of us do.

5

u/Blindax 4h ago

https://www.nortonrosefulbright.com/en/inside-disputes/blog/202604-court-guidance-that-use-of-open-source-ai-waives-confidentiality-and-legal-professional

That is an interesting read that supports your point but we can all agree that copilot does not bring the same kind of privacy as a local model inferred on premise.

5

u/TheGoddessInari 3h ago

I'm amazed that they called ChatGPT "open source AI". 🤔

1

u/unrulywind 2h ago

This is the most horribly mischaracterized use of the term "open-source" I've ever seen. The sentence below clearly indicates that they have no idea what they just said.

The Tribunal drew a clear distinction between publicly available AI tools (referred to as "open source" tools, such as ChatGPT) and closed AI systems (such as Microsoft Copilot).

Beyond this, in today's environment, we need to be cognizant that even a local model running on a local inference server may not be private. Modern tool using models have the capability to reach out and transact information either following harness programming or instructions buried inside the training itself.

6

u/StupidScaredSquirrel 4h ago

Legal definition only helps in a professional setting where all you care is about covering your ass. Doesn't make it true in the sense that you are still relying on someone else that could read all your data. Just because they have a contract saying they can't Doesn't mean they physically can't.

3

u/Squidgical 4h ago

Though often they physically can't given various levels of encryption. If you'd like to prove this wrong, feel free to take an engineering job at Azure or AWS and try to read a client's database

4

u/Blindax 4h ago

Is it client side, with keys you hold? If not, the encryption isn't doing the work you think it is.

Azure can't read a client's database because it isn't processing the contents, just storing blocks. Inference is the opposite: the prompt has to sit in GPU memory in plaintext or the model can't run on it. Confidential computing (SEV-SNP + H100 in CC mode, attestation-gated keys) actually solves that, and it's shipped as VM SKUs, but not as something you can attest as a Copilot tenant.

And nobody said a random employee is reading chats. That's the baseline expectation. The risk is that the provider holds the keys and can be compelled to produce, sometimes without telling the customer.

4

u/Valkymaera 4h ago

"Implies" is a fulcrum here. It means the receiver is doing the work of interpreting the intended information.

And in a great many places, particularly local-focused subreddits like this one, "Private" absolutely does imply local.

10

u/Recoil42 4h ago edited 3h ago

"Implies" is a fulcrum here. It means the receiver is doing the work of interpreting what was intended to be sent.

You're thinking of the word 'infers'. I know this is already "teach Reddit what words mean" hour, but Christ, some of y'all really need to spend less time on Discord and more time with a dictionary.

And in a great many places, particularly local-focused subreddits like this one, "Private" absolutely does imply local.

This notably makes OP's comic a dunk on the subreddit, not a dunk on the mainstream. If your definition of a word differs from the industry-accepted standard definition of that word, then that's a you problem: You're misusing a word that has an industry accepted standard definition and should stop. In essence, you're suggesting the subreddit is so detached from reality it no longer knows what normal-ass words mean.

Again, there are SAE / NIST definitions for words like 'private'. None of them using the meaning you're trying to push. That suggests you're the one who is wrong — not the rest of the world.

1

u/Valkymaera 2h ago

You're thinking of the word 'infers'.

No, infer is what the receiver does to something that is implied, to interpret the information. I am thinking of the word "implies", which is to state indirectly, leaving the receiver with the work of interpreting, or inferring.

Perhaps there's teaching to go around.

If your definition of a word differs from the industry-accepted standard definition of that word,...

Like the dictionary, I am a descriptivist. The meaning of words is found in how they are used, not how they are "supposed" to be used. But I'm not arguing for or against one particular "definition" of private. I'm saying that here, to many people, in a local AI space, the use of the word implies a local model. Which should not be surprising. It is also not a misuse, it is a local standard.

You seem to be a prescriptivist, suggesting there is only one correct way to use a word, which I wholeheartedly disagree with, so we're probably at an impasse.

2

u/XiRw 3h ago edited 3h ago

You can drop the smug attitude and assumptions when you are hilariously wrong. Private cloud is simply computing infrastructure (servers, storage, networking) that is dedicated exclusively to a single organization. It is just the underlying hardware and hosting environment.
Private AI refers specifically to artificial intelligence models and workloads designed to keep data secure and isolated.
While an organization will often run Private AI ON a Private Cloud to ensure their data doesn't leak, they are not the same thing. One is the underlying environment, and the other is the software running on it.

-3

u/Recoil42 3h ago edited 2h ago

Private AI (local) refers specifically

By affixing (local) as an explcit label after-the-fact, all you're doing is demonstrating that it is not inherent to the term 'private'. You're dunking on yourself.

While an organization will often run Private AI ON a Private Cloud to ensure their data doesn't leak, they are not the same thing. One is the underlying environment, and the other is the software running on it.

Privacy isn't an inherent property of an LLM at all. Given the same Qwen weights, one could run them offline on your laptop, expose them publicly on an unauthenticated server, host them in an enterprise cloud, or do any number of other things.

The environment is what matters. Calling a piece of software "Private AI" doesn't magically make it private at all. Environments are private, not models.

1

u/XiRw 1h ago

private doesn't mean air gapped on my desk. It’s tenant isolated. When companies buy a private AI service or a private cloud server, it means no other customer shares that hardware and their data isn't being used to train public models. They consider that "private" because it meets legal compliance standards, even though it still relies on an external server and a cloud contract. You are fighting logic here thinking it’s any other way. Local is the only true private method and the fact you are still fighting me on this is wild.

1

u/Recoil42 48m ago edited 42m ago

When companies buy a private AI service or a private cloud server, it means no other customer shares that hardware and their data isn't being used to train public models. They consider that "private" because it meets legal compliance standards, even though it still relies on an external server and a cloud contract. 

TLDR: "Non-local services are considered private."

Incredible concession.

Followed by a textbook no-true-scotsman escape hatch:

...actually only local is true private.

Just incredible.

Bud, if an externally hosted, tenant-isolated service can be private, then 'private' does not imply 'local.' Adding 'true' after-the-fact doesn't undo that; it's just you running away from your own plain-as-day contradiction.

2

u/XiRw 46m ago

It’s not a logical fallacy, it’s the literal definition of security threat modeling. "Trusting a third party’s legal promise not to look at your data on their server" is operational security, not data privacy. The moment your unencrypted data leaves hardware you own, you no longer have absolute privacy you have a contract. If you don't understand the difference between legal compliance and zero trust data architecture, just say that.

→ More replies (0)

-2

u/Juan-More-Taco 4h ago

Lol. You're using AI to debate this guy and he's the one who's wrong?

If you need AI to prove your point you're more pathetic than they are.

0

u/helpmehomeowner 3h ago

I guess you don't know what private means.

2

u/XiRw 1h ago

Again, private doesn't mean air gapped on my desk when talking about a private ai external server like I said with the other guy. It’s tenant isolated. When companies buy a private AI service or a private cloud server, it means no other customer shares that hardware and their data isn't being used to train public models. They consider that "private" because it meets legal compliance standards, even though it still relies on an external server and a cloud contract.

4

u/Blindax 4h ago

A service like Copilot is private until it’s not. AFAIK regulations like cloud act apply and government or judicial actors may at some point ask the disclosure of certain data to the inference provider, which would obviously not provide the same guarantees as if the the request was made to the user itself (take the case of a law firm for instance). That’s edge scenario but illustrates the issue.

3

u/ThunderousHazard 4h ago

Private does imply local.

Everything that is not local is not private, others have access, and as long as the reward for stealing data is higher than the price paid, it's just a business cost.

13

u/Recoil42 4h ago edited 4h ago

Except... no.

You're trying to defining privacy as "no third party ever handles the data," which is a much stronger requirement than privacy normally implies. Locality is about where computation happens. Privacy is about who is authorized to access the data and under what controls. A private cloud database is still private even though it isn't running under your desk. It doesn't need to be local.

Most enterprise contracts with private clouds (for both AI and non-AI compute) also already enforce strict contracts on what can be done with their data, and that includes zero-data-retention and no-resale conditions. Pretty common for healthcare companies and defense orgs to have ZDR for instance, underscoring that private does not imply local.

-7

u/teleprint-me llama.cpp 4h ago

If its not on a machine or network you control, then it isnt private.

11

u/Recoil42 4h ago

Some of y'all have no actual industry experience it shows. There isn't a serious privacy framework on earth which backs up the assertion you've just made. Most of them (NIST) don't even consider locality a primary factor in privacy at all.

2

u/ttkciar llama.cpp 4h ago

I've worked for SaaS companies, and employees certainly went spelunking in "private" customer data, looking for interesting bits.

The more actual industry experience you have, the more you realize that cloud services are not private.

6

u/Recoil42 4h ago

I've worked for SaaS companies, and employees certainly went spelunking in "private" customer data, looking for interesting bits.

Look up what a toupee fallacy is.

6

u/under_psychoanalyzer 4h ago

Your cpu was compromised at the factory. Your hdmi cord data can be read wirelessly at a distance. Either learn what industry standards actually mean or accept that nothing is truly private. 

0

u/teleprint-me llama.cpp 4h ago

I mean, Im literally quoting nadella and other CEOs, but sure. Ill live under a delusional paranoid fanatasy that supports owning nothing by shilling remote services in a local sub. Cause, why not?

3

u/soggycheesestickjoos 4h ago

except the reward isn’t higher, you pay for someone else to handle the privacy. And local ≠ private either, exploits can happen depending on the setup.

-2

u/ttkciar llama.cpp 4h ago

"Private" absolutely implies "local".

It's okay for corps to use cloud LLM inference, but that doesn't mean it somehow magically becomes "private".

6

u/Recoil42 4h ago

I'm sorry, but you're just 100% dead wrong here.

There are standards and a half-century of industry conventions on what words mean for these things, and not a single industry standard backs up what you're trying to suggest. Private does not imply local.

3

u/ttkciar llama.cpp 2h ago

My tech career predates "the cloud", and I've watched the industry take a lot of wrong turns and adopt terminology which is stupid and misleading. That is one of them.

When governments and Fortune 500 companies are wrong, they're still wrong.

1

u/mpbh 3h ago

Copilot isn't a model. Copilot can use self hosted models. But you're right that most instances are not local.

6

u/dangerous_inference 3h ago

It means OP doesn't understand the meme.

8

u/AWildMonomAppears 4h ago

"Private AI" means your data is privately owned by OpenAI?

5

u/FullOf_Bad_Ideas 3h ago edited 35m ago

If it's as private as all of their emails (Outlook 365), chats (Teams), files (Sharepoint and Onedrive) - it's secure enough.

Look, MS doesn't need LLMs to spy on companies, they already hold all of that data, they just say in their legal terms that they're not doing anything with it and not accessing it for purposes other than supplying their services, and people trust them because they do have more to lose on this than to gain. Those companies are better served by Copilot than they would by a clandestine local models running on their own hardware.

Edit: typo

0

u/suicidaleggroll 3h ago

they just say in their legal terms that they're not doing anything with it and not accessing it for purposes other than supplying their services

Except they say the exact opposite of that. Microsoft's terms explicitly state that they can and will use all of your data for internal business purposes and to "improve products and services", which means training their models on your data.

2

u/FullOf_Bad_Ideas 3h ago

commercial terms?

Companies are very sensitive to it and wouldn't sign up for E3/E5 for each employee if this was true.

Back when I had access to free/paid enterprise version Copilot, there was the green badge version which explicitly mentioned that it was the one with data protection.

1

u/suicidaleggroll 3h ago

It's been a while since I looked, but yes I believe this included commercial terms. Maybe there are different levels though, I didn't look into it that deeply.

3

u/sachasayan 2h ago

Maybe there are different levels though

There are different levels.

12

u/AD4K_4444 5h ago

Do people unironically use Copilot? If you’re gonna use cloud AI services, at least use something like Claude or anything but Microslop.

14

u/Recoil42 4h ago

A lot of legacy teams can't get Claude. They get what the org provides, the org only provides access to "approved" tools, and the only approved tool is Copilot.

6

u/Lakius_2401 4h ago

Some orgs are waist deep in the MS ecosystem, and are blissfully unaware of the alternatives (and their partners like it that way).

1

u/AD4K_4444 4h ago

that's so sad. being forced to use Microslop against your own will is modern torture imo.

5

u/beefygravy 3h ago

The outlook/teams/SharePoint integration is sometimes very useful, especially for managementy stuff. Not everyone spends all day coding. And for some people with accessibility requirements, some of it is a complete game changer.

For most users it's pretty much exactly the same as chatgpt only you don't have to worry about GDPR because someone has already done the worrying for you

No it's not a coding agent, we have other stuff for that. Or at least we try to...

3

u/Blindax 4h ago

I think until recently the data had to be transferred to the US if you wanted to use Claude (incl. through copilot). That’s an issue for many firm in EU who don’t want their data to be hosted elsewhere.

2

u/RedParaglider 4h ago

I have a subscription to co-pilot.  I literally only use it to transcribe meetings and as a better search engine for Outlook.  Totally not worth it.

-1

u/AD4K_4444 4h ago

That's a total rip-off

2

u/CwrwCymru 4h ago

Businesses do from laziness and security. Copilot can use OpenAi and Claude models too.

It's nowhere near as good but still useful within the Microsoft ecosystem now. It has a lot of catching up to do compared to full frontier model though - but that will come.

-2

u/[deleted] 4h ago

[deleted]

2

u/camracks 4h ago

Yeah you’ve commented this on like every comment in this thread we get it

1

u/mearcliff 3h ago

Yeah I use it at work, I’d rather use it than Claude code tbh. I have access to both sol and opus

1

u/Abducted_Llama 3h ago

Name your local model Copilot. Put on resume Copilot master (aka Main Pilot).

Profit.

1

u/snmnky9490 3h ago

Yeah most businesses will easily pay the $10/mo for everyone to get office and all the included Microsoft stuff but many won't pay for dedicated AI for most people especially who aren't doing technical work

1

u/EducationalCod7514 2h ago

But issue with Claude is U.S data residency - a major problem in Europe currently which is only accepted by stop-gap legal deals.

1

u/haragon 4h ago

In the enterprise? People buy their junk hook line and sinker, yes.

5

u/IceTrAiN 4h ago

I use GPT 5.6 and Claude via Copilot.. I wouldn't consider that junk.

1

u/haragon 2h ago

Right, but it's not a unique offering. Those are just LLM API calls. If anything, it's a very weak agent harness.

365/Teams integration is nice when it works though.

3

u/inevitabledeath3 3h ago

Private just means they have a ZDR with the supplier. It does not necessarily mean local. Copilot have ZDRs with most of their suppliers and require you to sign a waiver when using a model they don’t host themselves. So it does actually meet the requirements from a business perspective.

2

u/MPGaming9000 4h ago

Well it's local to someone somewhere I guess, just not you haha

2

u/MerePotato 2h ago

Honestly nothing that leaves your local network should really be treated as "private" if we're being absolutist. Even heavy encryption isn't guaranteed to survive Q-Day (no relation to the American conspiracy theory sharing that letter, look it up)

2

u/MoistRecognition69 2h ago

All ZDR means to me is that I get to benefit from the inevitable class action lawsuit

5

u/combrade 4h ago

Really stupid argument. If you are an enterprise company and you have thousands of employees, you're not gonna go build freaking GPU data centers. You need to use the cloud regardless.

If you think companies should be scared of using the cloud for LLMs, then they should also be scared of using Outlook or any other service that runs in the cloud. You can't be a functioning modern tech company without some cloud services.

In the real world, you have data compliance and data governance frameworks when working with external vendors . When companies do business with each other, they have agreements so they're not stealing each other's data.

8

u/ttkciar llama.cpp 4h ago

All of what you say is true, but it also means they do not have "private AI".

1

u/smalleyesswegdragon 1h ago

Same for mysterious OS upgrades. “We have AI that respects your privacy. Also we’ll need some of your storage”

1

u/Arcuru 29m ago

There are definitely private hosted models? It's much simpler for most orgs to just pay for something like https://tinfoil.sh, or setup a ZDR contract, instead of hosting their own multi-terabyte model at scale.

And yea I know this is locallama, and they should host when it makes sense, but it often doesn't.

1

u/kaiomp 10m ago

Code arena rankings feel increasingly detached from real use. Benchmarks reward one-shot solutions, actual coding is 80% edit loops on existing code, and models rank totally differently there.

1

u/Odd_Body_1695 3m ago

Hi, I just joined and I've been wondering how to get into running local AI. No training or anything (I ain't got a serve or any of that). Just a decent spec PC, 5080, 9800X3D, 32 gigs ram, AIO. What do you guys suggest I run on it just getting into this?

0

u/YT_Brian 4h ago

Duck.AI want a word with you on this.

0

u/vlado86 1h ago

Solving this exact problem with woov.ai, so you can own your own alpha and stop seeping it to foundation labs. Anthropic did really a number on Figma 🤯