Open vs closed AI systems – the wall around your trustees’ AI

by | 26,Aug,2026 | AgendaWorx, Employee Benefits, Q3 2026

George Brown

As a trustee you carry a duty that predates every model and every vendor: keep members’ data safe. AI only raises the stakes. Before the board signs off on any AI tool, ask: Where does this thing run, and who gets to see what we feed it? Answer that honestly and you have already sorted the fund into one of two camps.

They are referred to as closed and open AI systems, though the words get thrown around loosely. Some people say “open” to mean open weights, models like Llama or Mistral whose internals you can download. That is a real distinction, but it is not the one that should worry a board. The distinction that matters is the boundary. Is the fund’s AI running inside a fence you control, or out in the open where the fund is merely a guest?

What a closed AI system actually is

A closed system is one where the compute, the data, and the governance all sit inside the fund’s perimeter. Azure OpenAI Service and AWS Bedrock are the polished commercial versions of this. Prompts run inside your own cloud area, member data is not used to train AI, and you get contracts, audit logs and regional controls. A locally hosted model on the fund’s own server, or on a controlled service provider’s server, takes the same idea to its logical end. Nothing leaves the building.

What closed systems share is not the model (e.g. ChatGPT or Claude). What unites them is the fence. You decide where the data lives, who touches it, and what happens to it afterwards.

Why is this now a compliance question?

Keeping member data safe is no longer only good practice. Joint Standard 2 puts the responsibility squarely on the trustees. The standard expects a sound cybersecurity strategy and requires you to manage the risk that third parties bring in.

That is where AI lives. Every time the fund sends member information to a public AI service, it hands data to a third party and inherits that party’s controls, or lack of them. A closed system keeps you on the right side of that line. An open one asks you to trust arrangements you did not write and cannot audit.

Many trustees reach for the convenient option: a personal ChatGPT Plus or Claude Pro account. That is an open system. Every prompt and response travel to OpenAI’s or Anthropic’s servers. On consumer premium accounts, the data can be used to train the models by default unless the user switches the control off. Even then, the information still leaves the fund’s control. There is no data processing agreement (DPA) with the fund and no contractual right to audit what happens to the content.

That is how retirement fund secrets and member data get exposed. A single trustee pasting a board pack summary into a personal premium chat has already moved that information outside the fund’s fence.

Open vs closed: How a board should actually choose

Do not start with the technology. Start with the data. Ask what would happen if the most sensitive member information you plan to send got out. If the answer is “a breach, a letter from the regulator, and a front-page story,” you want a fence. AWS Bedrock, Azure OpenAI, or a local deployment under the fund’s or a controlled service provider’s control are the grades of fence that keep the data inside.

If a fully closed deployment is not yet practical, the next responsible step is a business-tier account (ChatGPT Team or Enterprise) paid for by the fund. These come with a DPA, and, by default, the model is not trained on the content the fund feeds it. It is not as strong as a true closed system, but materially safer than a personal premium login:

Open tools are for the low-stakes work where speed wins; closed systems are for anything that would harm a member or fund if it strayed. Make sure your board understands which side of the AI fence a given task belongs on.

Zeldeen Muller
+ posts