You can get AI help with schema design with zero network egress: Schemity’s MCP server listens only on your own machine, so an agent host running a local model - LM Studio, for example, is an MCP host for local models - can read your diagram and stage edits you review, with no API key, no cloud call, and nothing crossing the network. For a lot of engineers, that is the difference between getting AI help with schema design and getting none, because their employer has banned cloud AI outright.

The bans have a famous origin story. In 2023, a Samsung engineer pasted proprietary database source code into ChatGPT to check it for errors. Within a month there were three incidents, and Samsung banned generative AI tools company-wide. Plenty of companies read that memo and wrote their own. If you design databases inside one of them, the policy does not say “be careful with AI.” It says no.

Notice what leaked in that first incident: database code. Not customer records, not credentials - the structure itself. Your schema is worth protecting, and your security team knows it. So the question for a lot of engineers in 2026 is not “which AI tool should I use for schema design?” It is “is there any AI help I am actually allowed to have?”

When is an approved cloud agent still too much?

We wrote before about AI database design without a vendor cloud in the middle: Schemity is an MCP server, so the agent you already use - Claude Code, Cursor - reads the diagram through your own machine, and the schema goes only to the model provider your company already approved for the code. For most NDA and IT-policy situations, that is the fix - no new relationship at all.

But some environments do not negotiate relationships. A blanket AI ban does not distinguish between “a vendor’s AI service” and “the agent we already pay for” - the schema still crosses the network to someone else’s servers either way. Developers handling client work describe exactly this wall: confidential client data that cannot be uploaded to a third party, full stop, no matter whose account it rides on. And on air-gapped networks or machines with no-egress policies, the argument ends before it starts: outbound calls are not slow or discouraged, they are impossible.

For these environments, a better contract is not the answer. Zero egress is the answer.

How does a local model connect to Schemity?

Schemity runs no model of its own. It exposes the diagram over the Model Context Protocol at http://127.0.0.1:7332/mcp, behind a token kept in your OS keychain, and any MCP host can connect - including hosts that run open models such as Llama, Qwen, or Mistral on your own hardware. LM Studio is one: it loads models locally and acts as an MCP host, taking a server URL and an authorization header in its mcp.json. The MCP panel in Schemity shows the URL and the token to paste.

Now walk the whole loop. Your diagrams are already plain JSON files on your disk - no account, no sync. Your database credentials already live in the OS keychain, and the agent never sees them. The MCP server binds to localhost and nothing else. And with a local model, the weights sit in the same place your diagrams do: on your hardware. A request goes from one process on localhost to another and back. Nothing crosses the network boundary, so there is nothing for a proxy log to catch, nothing for a DLP scanner to flag, and nothing for a client’s auditor to ask about.

An MCP server made the AI loop private: you and the agent you chose. A local model makes it local: you, and nobody.

That is AI ERD design without asterisks - AI without a cloud product in the loop, where even the model is a local file. On an air-gapped network, download the host and the model on a connected machine, move them across the gap the same way you move any approved software, and the setup works exactly the same. This is private AI database design in the literal sense: it works with the network cable unplugged.

What can a local-model agent do in the diagram?

Local does not mean lesser in what the agent is allowed to do. The server offers the same tools to every host: read the schema, context views and their dependencies, lint findings, and the impact of pending changes; stage entities and relationships; group entities into legends; route relation lines. Describe “a warehouse system with lots, batches, and expiry tracking” and it drafts the entities and relationships on the canvas. Every staged change goes through the normal undo history, and History names the agent that made each step, so undo works on the agent exactly as it works on you. Nothing it does writes to a database.

Honesty matters here: an 8B-parameter model on your laptop is not a frontier model in a datacenter, and small models are less reliable at calling tools correctly. Its first drafts will be rougher, and you will review them harder. But you were always supposed to review the drafts - the model proposes, you dispose - and for the environments this post is about, the comparison is not “local model vs cloud model.” It is “local model vs no AI at all,” because the cloud option was never on the table.

Why is this setup easier for IT to approve?

There is a quiet second benefit. When you ask IT to approve database design software with AI, the usual review drags because the answer to “where does the data go?” has three vendor names in it. With Schemity plus a local model the answer is one sentence: diagrams are local files, credentials are in the OS keychain, the MCP server listens on localhost, and the model is a local process. Database design software approved by IT is usually the one that gives the reviewer nothing to investigate - the same reason consultants keep client schemas in per-client local workspaces instead of a shared cloud account.

If your approved agent is allowed to see the schema, it is still the pragmatic choice - frontier models are better at first drafts and at using tools. But if your workplace read the same memo Samsung wrote, the choice is no longer “AI somewhere else or nothing.” Run a local model in an MCP host, paste Schemity’s URL and token, and the most honest document your business owns gets AI help without ever leaving the building.