6 min read

The 'Where' Matters More Than the 'Who': Assessing AI Risk for Associations

The 'Where' Matters More Than the 'Who': Assessing AI Risk for Associations

Many association executives feel a reflexive hesitation when they hear about powerful new artificial intelligence models emerging from international labs, particularly those in China. When a model like Moonshot AI’s Kimi K3 or Alibaba’s Qwen 3.8 Max claims to rival the intelligence of established American models, the immediate concern for many leaders is one of security. There is a common assumption that the origin of a model—the "who" behind its development—is the primary factor in determining its safety for organizational use. However, this perspective often overlooks the technical reality of how AI actually functions. In the world of association risk management, the most critical question is not where a model was born, but where it is being executed. By shifting the focus from the developer to the infrastructure, associations can make more informed decisions about which tools to adopt and how to protect their most sensitive member data.

The origin myth in AI data security

The fear that using a model developed in another country inherently compromises AI data security is often based on the idea that the model itself acts as a kind of "black box" that could secretly exfiltrate data. While it is vital to be cautious, it is equally important to understand the architecture of these systems. An AI model is essentially a collection of parameters and weights. Think of parameters as the synapses or connections between biological neurons in a brain. These weights determine how the model processes information and makes decisions. When a company like Moonshot AI releases a model as "open weights," they are essentially giving away the finished intelligence of the system. This allows other organizations to download those weights and run the model on their own hardware or within their own trusted cloud environments.

Because the actual code that defines the possibilities of what an AI model can do is relatively small—often thousands of lines rather than millions—it is much more observable than traditional software. This makes the existence of a hidden "backdoor" that could send data back to a foreign server extraordinarily unlikely, especially when the model is running on infrastructure you control. The real risk is not the model’s weights, but the service you use to interact with it. This is why the surrounding infrastructure and harness matter far more than the model itself. If you upload a sensitive membership directory to a public website hosted on servers outside of your jurisdiction, you are indeed providing your data to that provider. In that scenario, the risk is high because the data is leaving your sphere of control. But if you take those same open weights and run them on a server in your own office or within a secure, US-based cloud environment, the risk profile changes completely. The intelligence remains the same, but the data never leaves the secure perimeter you have established.

Understanding the AI supply chain: weights versus inference

To navigate this new landscape, association leaders must distinguish between the model developer and the inference provider. An inference provider is the company that hosts and runs the AI model for you. This is the "where" of the equation. For example, Microsoft Azure has already begun offering models from international labs, including various versions of the Kimi models, on its own hardware. When an association uses a model through a provider like Microsoft, Amazon Web Services (AWS), or Google Cloud Platform (GCP), the relationship is governed by the same enterprise agreements, cybersecurity standards, and terms of service that already protect the rest of the organization’s digital assets. These providers offer a "walled garden" where the intelligence of the model can be utilized without the data being used to train future models or being accessible to the original developer.

This distinction is becoming more important as AI intelligence becomes a commodity. Just as a driver might not have a strong loyalty to a specific brand of gasoline if the product is identical and the price is lower at a different station, organizations are beginning to look for the most efficient model for the job. Microsoft, for instance, has explored using different models for various tasks to lower its own operational costs, sometimes saving hundreds of millions of dollars by switching workloads to more efficient, open-weight models. For an association, this means you might use a top-tier, highly secure American model for complex strategic planning, but a more cost-effective open-weight model for routine member service inquiries. As long as both are running through a trusted inference provider, the AI data security remains consistent. The goal is to use the best engine for the task while ensuring the fuel—your data—stays in a secure tank.

The security of trusted inference providers

When evaluating a new AI tool, the first step in association risk management should be to ask where the inference is happening. If a third-party vendor claims to use a powerful new AI model, you must verify which cloud infrastructure they are using to host that model. If they are running it on their own proprietary servers in an unverified location, that should be a red flag. However, if they are using a reputable, US-based provider, they are likely subject to rigorous compliance standards like SOC 2 or HIPAA. This allows your association to leverage the rapid advancements in AI intelligence without having to wait for a specific domestic lab to catch up. The pace of innovation is so fast that waiting six months for a "preferred" developer to release a similar feature could mean missing a critical window to provide value to your members.

Furthermore, the level of intelligence required for most association tasks does not always demand the most expensive or "genius-level" model. For many business processes, such as summarizing committee notes or categorizing member feedback, a model that is "good enough" is often more than sufficient. By using open-weight models through trusted providers, associations can access high-level intelligence at a fraction of the cost of proprietary, closed models. This economic shift, driven by the rapidly shrinking cost of AI models, allows for more ambitious projects, such as personalized learning paths for every member, that might have been cost-prohibitive just a year ago. The key is to ensure that the infrastructure remains the primary focus of your security audit, effectively addressing the infrastructure gap that often holds back organizational strategy.

Closing the gap on unauthorized AI note-takers

Once you start asking where the inference is happening, that question applies to more than just the large language models under formal review. It applies to every tool touching your data, including the ones already in use. AI note-takers are a good example, and a much more immediate risk than the origin of any model. These bots join Zoom or Teams meetings to record audio and generate transcripts, and they rarely go through the same evaluation an enterprise AI tool would. Many of them are shadow AI, brought in by individual employees or external meeting guests without any formal vetting by IT or leadership. When an unauthorized note-taker enters a meeting, it is essentially a third-party observer recording every word of a potentially sensitive conversation. You have no control over where that audio is stored, who has access to it, or whether it is being used to train other models. That is the data leaving your secure perimeter, which is exactly the scenario the model origin debate is meant to prevent.

The fix is the same standard applied evenly. Associations should implement clear policies prohibiting the use of unauthorized third-party AI note-takers in any internal or member-facing meetings, and pair those policies with approved alternatives so staff have a legitimate option. This matters because meetings are often where the most sensitive strategic discussions occur. The built-in AI features of a platform like Microsoft Teams or Zoom, provided they are covered under your organization's enterprise privacy settings, keep the recording inside the walled garden you already control and already audit. That is far safer than allowing a bot from a startup with unknown data practices to sit in on your board meeting. Protecting your data means staying vigilant about the convenient, low-level tools as well as the high-profile model decisions.

A framework for association risk management

To thrive in this era of rapid AI advancement, association leaders must move beyond a binary view of "safe" versus "unsafe" models based on their country of origin. Instead, adopt a framework that prioritizes data sovereignty and execution environment. First, educate your team on the difference between model weights and inference. This knowledge prevents the organization from being paralyzed by headlines about international AI competition and allows you to focus on practical adoption. Second, establish a list of approved inference providers. If a model can be run within your existing secure cloud environment, it should be considered for use regardless of who developed the initial weights. This approach ensures that you are always using the most capable and cost-effective tools available.

Finally, remember that risk management is an ongoing process of education rather than a one-time set of rules. As models become more agentic—meaning they can take actions like browsing the internet or accessing your database—the risks will evolve. Understanding the security risks associated with connecting AI to your data becomes paramount as these tools gain more autonomy. However, this risk is again tied to the permissions you grant the model and the environment in which it operates, not the model's birthplace. By focusing on the "where," associations can build a robust AI strategy that is both secure and agile. You can afford to be model-agnostic as long as you are infrastructure-obsessed. This mindset allows you to serve your members with the best technology the world has to offer while keeping their trust and their data firmly under your protection.

Why 'Flash' Models Are the New Workhorse for Association AI Agents

1 min read

Why 'Flash' Models Are the New Workhorse for Association AI Agents

For the past few years, the narrative surrounding artificial intelligence has been dominated by a single, relentless pursuit: the race for the...

Read More
Intelligence as a Commodity: Why Your AI Strategy Must Be Model-Agnostic

1 min read

Intelligence as a Commodity: Why Your AI Strategy Must Be Model-Agnostic

Many association leaders feel a quiet pressure to pick a side. In the early days of any technological shift, we look for the winner—the one platform...

Read More
The New Reality of Government-Gated AI: Why Your Association Needs Options

1 min read

The New Reality of Government-Gated AI: Why Your Association Needs Options

Imagine a high-security research greenhouse where the most advanced botanical specimens are kept. For years, scientists and enthusiasts alike could...

Read More