Skip to content
Skip to content

Custom LLM for Sydney Enterprises

We are a Melbourne consultancy, we have no Sydney office, and we do not own a data centre. What we build is a model that runs inside infrastructure you control, which turns out to be the only version of “data sovereignty” your board can actually verify.

0
Sydney offices, NSW staff or dedicated account managers we have
0
data centres Yes AI owns or operates, here or anywhere
1
city we actually operate from, which is Melbourne
100%
Australian owned and operated

No Sydney Office, and No Sydney Data Centre

This is not a confession. It is the part of the pitch most vendors handle with a serviced office, a facility name they have no relationship with, and a latency figure nobody measured.

Search for AI deployment in Sydney and you will be told about Tier IV facilities, sub-200-millisecond latency, dedicated local teams and same-day on-site support. Follow enough of it and a pattern emerges: the data centre belongs to someone else entirely, the latency figure was never measured on anyone's actual workload, and the local team is a national team with a Sydney phone number. It is a small, standard dishonesty, and it is worth noticing that it is aimed squarely at the most heavily regulated buyers in the country.

So, plainly. Yes AI is a Melbourne consultancy. We have no Sydney premises and no NSW staff. We do not own, operate or lease a data centre anywhere, and we will not name facilities to borrow their credibility. Sydney clients are served remotely, in the same time zone, by the same senior people from the first call to the handover. If an engagement genuinely needs us in a room (a large workshop, a board presentation) we fly up and it appears as a line item you can see and decline.

Here is why none of that costs you what you might assume. In this architecture, we are not the host. The model is open-weight and it runs on your hardware or in your own cloud tenancy, under your account, inside your security boundary. So the interesting question was never where our office is. It is whether your data ever reaches a model provider in another jurisdiction, and in a self-hosted deployment it does not, because there is no model provider. That claim is verifiable by your own network team rather than taken on trust from ours.

Which is the whole argument for Sydney specifically. A larger share of businesses here either are regulated entities or serve them, and serving one means inheriting its procurement standards, which now routinely include an AI questionnaire. “Our vendor assures us the data is safe” is a weaker answer than “the data never left our tenancy, and here is the architecture.” Sovereignty in this market is not a marketing word. It is a procurement argument, and it is one of the few that gets stronger the more carefully it is examined.

Built for the Regulated End of the Market

Sydney's density of financial services, insurance and the firms serving them changes what a sensible AI deployment looks like.

Financial Services and Insurance

Sydney holds a disproportionate share of the regulated end of the Australian market, and AI in a regulated business is a different exercise from AI in a services firm. The question is not whether the model works. It is who your operation now depends on.

  • No model provider to assess as a material service provider, because there is none
  • Designed for substitution: the model sits behind an interface
  • Measured evidence of performance rather than a vendor benchmark
  • Risk and compliance in the room from week one, not shown the result

Cross-Border Disclosure, Removed Rather Than Managed

Sending personal information to an overseas model provider is a disclosure under the Privacy Act 1988, and it needs treating as one, assessed, documented, defended, and still your accountability afterwards. Self-hosting deletes the question instead of answering it.

  • No personal information sent to an offshore model provider
  • No cross-border disclosure to assess, document or defend
  • The weights sit on your infrastructure, so there is nobody to disclose to
  • The architecture is the control, not a contractual assurance about someone else

Professional Services and Client Confidentiality

The firms serving the regulated end inherit its expectations. Your enterprise clients are sending AI questionnaires now, and "we have not thought about it" is a procurement loss well before it is a compliance problem.

  • Matter-level isolation for client confidential information
  • A governance position that survives a client assurance questionnaire
  • Practice and precedent knowledge retrieval inside your own network
  • A data residency answer that is architectural rather than aspirational

Where the Deployment Actually Runs

We do not own a data centre and we are not going to imply otherwise by naming facilities we have no relationship with. The model runs on infrastructure you choose and control, and you can go and look at it.

  • Your own hardware, on your own premises, if that is the requirement
  • Your own cloud tenancy in an Australian region, under your account
  • Your controls, your logging, your retention policy. It is your environment
  • We take custody of your data at no point in the engagement

NSW Government Contracts

A NSW government contract can pull your AI project into a state regime you had not budgeted for. It catches more private businesses than expect it, and it arrives through the contract rather than announcing itself.

  • PPIP Act obligations reaching you through contracted service arrangements
  • Data residency commitments that are verifiable rather than asserted
  • Documentation your customer's assurance team can genuinely review
  • An honest read on which obligations apply, not a recital of all of them

Consumer-Facing AI and the ACL

Australian Consumer Law applies to anything your AI says to a customer. An automated misrepresentation is still a misrepresentation, and no regulator has yet accepted "the model generated it" as an explanation.

  • Human review where a decision affects access to a product
  • Grounding in your own documents rather than model recall
  • Audit trails built in rather than retrofitted afterwards
  • Claims and representations reviewed before they are automated

The Layer That Makes This a Board Question

Not a recital of every rule. The four that most often decide whether a Sydney AI project is a procurement problem or a procurement advantage.

APRA CPS 234: Information Security

Information security capability must be commensurate with the threat, and information assets managed by a third party are explicitly in scope. An offshore model provider holding your data is a third party in that frame. One whose environment you cannot inspect. Bringing the model inside your own boundary moves the asset into an environment you already assess. It does not discharge the obligation; it relocates it somewhere you can actually discharge it.

APRA CPS 230: Operational Risk Management

Critical operations and material service provider management are board-level concerns. An AI system embedded in a critical process is squarely in that conversation, and a model provider your operation depends on can be a material service provider. The design consequences are real rather than documentary: substitutable providers over deep single-vendor commitments, genuine fallback paths over an error page, and measured evidence that the thing works rather than a vendor benchmark.

Privacy Act 1988 (Cth) and the Australian Privacy Principles

Sending personal information to an overseas model provider is a cross-border disclosure, and you remain accountable for what happens to it afterwards. Self-hosting is not a loophole around that rule. It removes the disclosure entirely, because there is nobody offshore to disclose to. That is a genuinely different argument to put in front of a board than a contractual assurance from a vendor in another jurisdiction.

Privacy and Personal Information Protection Act 1998 (NSW)

Covers NSW public sector agencies and can reach private businesses through contracted service arrangements. If you hold a NSW government contract, this may apply to your AI project, and discovering that mid-build is an expensive way to learn it. The obligation typically arrives through your contract rather than the statute, which is exactly why it gets missed.

General information on how these obligations typically apply, not legal or compliance advice. We work alongside your risk, compliance and legal functions rather than around them, and no deployment architecture makes a prudential standard go away.

How a Sydney Deployment Works

Remote from Melbourne, deployed into infrastructure you own, evidenced against your real tasks rather than a demo.

1

Remote Assessment From Melbourne

Systems review, data assessment and architecture are done on screens, in your time zone, by the people who will build it. Nobody has ever produced a better architecture because they were in the building. If a workshop or a board presentation genuinely needs a room, we fly up and it is a visible line item.

2

Deployment Into Infrastructure You Control

The model is deployed to your hardware or your Australian cloud tenancy, under your account and your controls. We do not host it and we take custody of your data at no point. There is no Yes AI data centre in this story, because there is no Yes AI data centre.

3

Evidence, Then Handover

Measured evaluation against your real tasks rather than a demo, documentation your risk and compliance functions can actually review, and an operating handover so your own people run it. When a question needs your lawyers rather than us, we will say so.

Explore by Industry or Location

Custom LLM serves Sydney businesses across every industry. Explore solutions tailored to your sector, or the city we are actually in.

APRA CPS 234 and AI

What the information security standard actually requires of an AI deployment, and what no architecture can do for you.

Understand CPS 234 →

Custom LLM for Financial Services

Private AI for banking, wealth and insurance, built for businesses whose regulator has opinions about their service providers.

Explore financial services AI →

Custom LLM Melbourne

Where we are actually based, and the one city where being in the room is a given rather than a line item.

Explore Melbourne deployment →

Frequently Asked Questions

What Sydney businesses ask before engaging a consultancy that is not down the road and does not own a data centre.

Do you have a Sydney office?

No. Yes AI is a Melbourne consultancy. No Sydney premises, no NSW staff, no dedicated account manager down the road, no quarterly workshops at an office we do not have. We are telling you on the page rather than after you have signed, because the alternative, a serviced-office address and a "local team" that is a phone number, is common enough in this industry that being straight about it is apparently a differentiator. What you get instead is the same senior people for the whole engagement, in the same time zone, on video like every other professional relationship your business already runs that way. If an engagement genuinely needs us in a room in Sydney, for a large workshop or a board presentation, we fly up and it appears as a line item you can see and decline.

Where is the data hosted for a Sydney deployment?

Wherever you decide, because you host it. This is the part worth being precise about, since it is where AI vendors are at their vaguest. Yes AI does not own or operate a data centre, not in Sydney, not anywhere. We are not a hosting company and we are not going to imply we are one by naming facilities we have no relationship with. What we build is a deployment that runs on infrastructure you already control: your own hardware on your own premises, or your own cloud tenancy in an Australian region, under your account and your billing. The data residency answer is therefore yours to give and yours to verify, which is a considerably stronger position than taking ours on trust.

Is a local deployment actually faster than an offshore API?

Usually, but we are not going to quote you a number we have not measured on your workload, and you should be suspicious of anyone who does. Network round-trip time to a US region is real physics and it is not small, so removing it helps. But total response time for a retrieval-based system is dominated by things that have nothing to do with geography: how many documents you retrieve, how large the model is, what hardware it runs on, and how many people are querying at once. A badly sized local deployment is slower than a well-run offshore API, and we have no interest in selling you the first while implying it beats the second. If latency genuinely matters to your use case, we measure it during the assessment against your actual queries and show you the distribution rather than a headline figure.

Does self-hosting satisfy CPS 234 or CPS 230?

No, and this is the most important sentence on the page for an APRA-regulated reader. Self-hosting does not discharge a prudential obligation. It changes the shape of the problem. Under CPS 234, information assets managed by a third party are explicitly in scope, so an offshore model provider holding your data is something you must assess and defend; bringing the model inside your own boundary moves that asset into an environment you already assess, but you still have to secure it, and now you own the whole of that job. Under CPS 230, the calculus is similar: a model provider your critical operation depends on may be a material service provider, and removing the provider removes that particular assessment while leaving you accountable for the operation itself. Anyone telling you a deployment architecture makes a prudential standard go away is selling something. Your risk and compliance functions belong in this from week one, not shown the result.

What does it cost?

Plans start at $2,999 per month, with tiers at $7,999 and $14,999 depending on model size, data volume and integration complexity. Pricing is the same regardless of which city you are in. There is no Sydney premium, and equally no Sydney discount, because the work is the same work. The full breakdown is on the pricing page rather than hidden behind a discovery call. What is genuinely variable is infrastructure: if you self-host on your own hardware, you are buying GPUs, and that number depends entirely on your concurrency and the model you land on. We would rather put that in front of you in the assessment than let it arrive as a surprise later.

Which NSW-specific rules matter?

For most private-sector Sydney businesses, federal law does the heavy lifting, the Privacy Act 1988 (Cth) and the Australian Privacy Principles, plus Australian Consumer Law for anything customer-facing. NSW-specific regimes bite when you touch the state sector: the Privacy and Personal Information Protection Act 1998 (NSW) covers NSW public sector agencies and can reach private businesses through contracted service arrangements. That catches more organisations than expect it. A NSW government contract can drag your AI project into a regime you had not budgeted for, and it usually arrives through the contract rather than the statute. We map which of these actually apply to your use cases rather than reciting all of them. This is general information on how these obligations typically apply, not legal advice.

Sovereignty Beats a Postcode

Every vendor in your stack now has an AI module and a meeting request, and most of them are asking you to send your data somewhere you cannot inspect. Start with a call from someone who will not be hosting it either, because you will be.

Sources and further reading