AI Adopters Club

AI Adopters Club

What "Private AI" Actually Means: The University of Florida's NaviGator in Practice

The University of Florida tags all 104 of its AI models with the data each one is allowed to receive. That tagging, not the supercomputer underneath it, is what does the protecting.

Kamil Banc's avatar
Kamil Banc
Jul 25, 2026
∙ Paid

Hi Adopter,

There’s probably a file on your computer you wouldn’t paste into ChatGPT. Maybe it’s a customer list, maybe it’s a contract, maybe it’s the thing your legal team has opinions about. You know exactly which one I mean.

Most companies handle that file with a policy nobody reads. Or a ban, which people route around within a week.

That gap is the whole reason I built Right Click Prompt. Same problem, smaller scale: if the prompt you want people using isn’t one right-click away, they’ll write their own. Early adopter rate is open until August 5, $36 a year locked forever.

The University of Florida had the same problem, just worse. Student records under FERPA, clinical data, unpublished research, export-controlled work, and a whole campus of people who wanted AI yesterday. So they built their own: NaviGator AI, running on HiPerGator, their own supercomputer.

And look, they spent real money on it. A $70 million AI initiative in 2020, another $33 million on Blackwell hardware, roughly $6 million a year just to keep it cool and running. Easy to look at that and think, well sure, they solved it by being rich.

But the supercomputer isn’t the part protecting the data.

Every model in NaviGator carries a tag saying which classes of data it’s allowed to receive. All 104 of them. The ones running locally on UF’s own GPUs are cleared for open, sensitive and restricted data. The frontier cloud models, the GPT and Claude and Gemini everyone actually wants, are cleared for open data only. Same chat box, same login. The tag on the model is the whole control.

So the crown jewel of a nine-figure AI program is, honestly, a permissions column in a table. Which is the good news, because a permissions column is free.

What I like about UF is they say the awkward part out loud. Straight from their own documentation: “When interacting with cloud models hosted by vendors, your messages and subsets of your documents will be sent to a LLM instance provided by Microsoft, Amazon, or Google.” Then, same breath, “None of this data contributes to training the large language model.”

That’s a hybrid, and they’re straight about it. A front door that decides which way your request goes, and they tell you when yours goes outside the building. Almost nobody selling you “private AI” this year is that specific about where your text ends up.

Get the 15 page deep dive case-study on this topic in the premium section.

Below the line I get into the questions this raises about your own setup:

  • How do you build the three-tier version of this when you’ll never own a GPU, and what does each tier actually cost you?

  • Where does this design still leak, and why has UF left that gap open on purpose?

  • Is a “private” tier ever real, or is it always theater? Their clinical model settles that one.

  • Are your own AI rules actually enforced, or just written down somewhere? Five questions will tell you.

  • What has to be true before you let any cloud model near a regulated data class?

If you’ve got data you can’t paste into a chat box, this is the one.

This post is for paid subscribers

Already a paid subscriber? Sign in
© 2026 Kamil Banc · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture