A general-purpose assistant in the model provider’s cloud: company account, SSO, admin panel, assurance that company data does not train the models. Data and chat history on the provider’s side, under the terms of the contract
ChatGPT Enterprise, Microsoft 365 Copilot or your own AI environment — a comparison for companies and public bodies
The three paths to AI in an organisation differ not in the licence price but in where the data goes, who is responsible for AI Act compliance, what leaving costs and whether an assistant’s answer can be checked at the source. A comparison in seven dimensions, with no advertising of other brands — as of 3.10.2026
Three paths to AI in an organisation
The question “ChatGPT or Copilot” is in practice a question about three different architectures. The first two are provider services in which the organisation is a subscription customer; the third is an environment the organisation controls — and for which it is responsible in the same way, but with the tools to prove that responsibility. The descriptions concern categories of service according to the providers’ public documentation; the terms of specific plans change and must be checked on the day of the decision
An assistant built into the office suite: works on documents and e-mail within the organisation’s tenant, with the user’s permissions. Model and processing in the provider’s cloud, integration mainly within its ecosystem
An environment in the organisation’s infrastructure or at a chosen operator: a gateway to many models, an assistant answering from your own documents with a source citation, a query log. The organisation decides where the data is and which model — and has evidence of control
A comparison in seven dimensions
| Dimension | ChatGPT Enterprise · Microsoft 365 Copilot | Own AI environment (SAIE) |
|---|---|---|
| Cost | Subscription per user; the cost grows with accounts and usage, and the provider sets the price list. The cost of switching providers is not on the price list | The cost of the environment and the models is planned from user to process; multiple budgeting levels. The full three-year bill — section 05 |
| Data | Data leaves the organisation for the provider’s cloud; contractual assurances (no training, encryption, region), but metadata and jurisdiction on the provider’s side; there is no on-premises version | The organisation chooses the location: on-premises, EEA or global; personal data masked before the model, WORM query log |
| AI Act | The deployer is the organisation — the system register, literacy (Art. 4), content labelling (Art. 50) and documentation remain on its side; the provider’s tools support but do not prove | The same duties, but with artefacts: system register, access policies, logs and the CDF methodology leading step by step to evidence of control |
| Lock-in | Own APIs, formats, identity and prompts in the provider’s ecosystem; the cost of leaving grows with every process deployed | Models interchangeable behind the gateway, processes and knowledge recorded in the organisation’s environment; changing the model does not change the process |
| Model choice | The provider’s catalogue; model versions and retirements outside the customer’s influence | More than 100 models through one gateway — including Polish ones (Bielik, PLLuM) and models run locally; model change without process change |
| Control | Admin panel: users, policies, usage reports; auditing of queries and answers limited to what the provider exposes | A log of queries and answers inside the organisation, answers with a source citation, budgets per team, human oversight under Art. 14 and 26 ready to prove |
| Time | Start in days — account and licences; the business process is added by an integrator or stays with a general assistant | The organisation’s processes deployed in 2 weeks under the CDF methodology; further ones in the rhythm of phases F0–F6 |
What is the same on every path
The choice of path does not change who is responsible. Under the AI Act the organisation is the deployer of an AI system used at work — regardless of whether the assistant runs in the provider’s cloud or in the server room. What changes is only whether it has the tools to prove that responsibility at a KRiBSI inspection from 28.10.2026
The organisation, not the provider and not the employee — the system register, literacy under Art. 4 and no prohibited practices under Art. 5 must be proven on every path
The service provider is a processor — a data processing agreement is needed (Art. 28 GDPR) and an assessment of whether the data may leave the organisation at all
From 2.08.2026 AI-generated content published in the public interest and deepfakes must be labelled (Art. 50) — the procedure is on the organisation’s side
An inspection asks about the register, logs, policies and training — not about the assistant’s brand. The difference between the paths is how easy that evidence is to gather
One deployer on every path — the organisation. The assistant’s brand does not transfer responsibility; it only changes whether, at an inspection from 28.10.2026, you have a register, logs and citations instead of declarations
When to choose what
Three typical situations — no ranking. Each path has its use, provided the decision is made after checking what data will be involved
The team works on content that may leave the organisation (marketing, public materials) and does not need answers from its own documents. A provider service is enough — with an AI use policy and a system register
The organisation works in one provider’s office suite, the data may be in its cloud and the processes fit its ecosystem. The suite’s assistant — with a permissions review and content labelling
Professional secrets, sensitive data, high-risk systems, an on-premises or EEA requirement, a need for source citation and audit. Your own environment — with a model gateway and an assistant on your own documents
What it really costs
components of the full cost — the first offer usually shows only the first
How much does an AI environment really cost?the comparison horizon — an annual subscription hides the cost of switching providers and rebuilding processes
TCO, not a price listthe bill that makes sense: cost per user and per process over 3 years, not a licence price per month
user × process × 36 monthssubscription per user, or tokens and models behind the gateway
the provider’s cloud included in the price, or your own server room / operator
updates, service, SLA — at the provider or in the contract
Art. 4 training, administrators, process owners
from an account in days to a process in weeks — who deploys it
prompts, formats, identity, integrations — grows with every process
Can you spot an AI hallucination
Five answer pairs from regulated fields — in each one answer is made up. Instant score and one rule that tells them apart
Which answer is made up
In each pair, point to the answer that is made up. The score is calculated immediately, nothing is sent. Every true answer has a basis you can check — that is the clue
How it looks in SAIE
An AI workspace: domain assistants and answers from the organisation’s documents with a source citation — a trace of what the result was based on
PROXY:AIOne gateway to more than 100 models: access policies, data masking, budgets and a WORM query log
Deployment and securitySaaS, on-premises or air-gap — the organisation chooses where the data is; architecture and seven ISO standards
Sources
- Regulation (EU) 2024/1689 (AI Act), Art. 3, 4, 5, 14, 26, 50
- Regulation (EU) 2016/679 (GDPR), Art. 28, 32, 35
- Act of 3 July 2026 on artificial intelligence systems, Journal of Laws 2026 item 1003
- SAIE vs open source vs hyperscaler comparison — allclouds.pl, section 06 of the SAIE Products page
- “How much does an AI environment really cost?” — episode 1 of the series “Four questions before choosing an AI environment”
- Providers’ public documentation (terms of business plans) — as of 3.10.2026
Informational material, not legal advice or an offer. Other providers’ product names are their trademarks and are used only for identification. As of 3.10.2026
Questions about choosing an AI environment
Is ChatGPT Enterprise compliant with the AI Act?
The AI Act does not certify assistants. The deployer’s duties — system register, literacy, content labelling, no prohibited practices — rest with the organisation regardless of the chosen service. The provider can help with documentation, but the organisation gathers the evidence
Does Copilot send company data outside the organisation?
Processing takes place in the provider’s cloud, within the organisation’s tenant and under the provider’s contract terms (region, no training). For an organisation with an on-premises requirement, or one that cannot entrust data to an external processor, this criterion decides before the price does
Does your own AI environment mean building from scratch?
No. Your own environment is a ready platform — a model gateway, an assistant on documents, a log — deployed in the organisation’s infrastructure or at an operator in the EEA. It differs from open source in service, contract and methodology; from provider services in that the data and processes stay in the organisation
How do you compare the cost of a subscription and your own environment?
Over the same horizon (3 years) and the same components: licences or models, infrastructure, maintenance, competences, deployment time and exit cost. The licence price per user is one of six elements
How can you tell that an assistant made up an answer?
By the lack of a source. A language model answers fluently even when it has no data — hence non-existent articles of law and dates. An assistant working on the organisation’s documents (RAG) gives a citation and the place in the document; no source, no answer. The quiz in section 06 shows this on five pairs