Private AI & sovereign AI

Sovereign AI for companies – control data, models and operations

GDPR requirements, confidential company data and AI workloads need controllable data flows – but not automatically your own server. The key is an operating model that balances protection needs, models, integrations, cost and operations.

I design and implement sovereign AI architectures without vendor dogma: public cloud, EU-hosted AI, private cloud, local AI on your own infrastructure or hybrid AI. Privacy and GDPR requirements are engineered into the design without pretending self-hosting automatically creates compliance. The goal is the smallest controllable architecture without unnecessary vendor lock-in.

Decision framework
Data & risk
Processing matched to protection needs
Operating model
Public, EU, private, on-premise or hybrid
Integration
Existing systems and permissions considered
Portability
Lock-in and switching cost consciously limited
Architecture problem

Data sovereignty is not a single hosting feature.

A “private LLM” can have very different control boundaries depending on provider and setup. A sound decision has to consider data location, contracts, model access, network, permissions, hardware, updates, scaling and integrations together.

Data & protection needs

Which information may be processed in which environment? Personal, confidential or regulated data needs different guardrails from public content.

Operations & model access

A local model increases infrastructure control but adds hardware, update and operational work. Managed cloud can be faster when the protection need permits it.

EU AI Act & data protection

AI literacy measures under Article 4 have applied since 2 February 2025. Article 50 transparency obligations have applied since 2 August 2026, depending on role and system. Technical architecture does not replace case-specific legal assessment.

The useful answer is therefore not “cloud bad, on-prem good”, but an operating model whose control level fits the workload and can actually be operated day to day.

Architecture by label

  • “EU” or “private” without checking actual data flows
  • On-premise without budget for operations, updates and hardware
  • Public cloud without suitable contractual and permission boundaries
  • A vendor becomes the architecture instead of a replaceable component

Architecture by requirement

  • Protection needs and processing paths first
  • Operational effort and model requirements priced realistically
  • Permissions, logging and integrations considered from the start
  • Portability and exit path deliberately planned
Operating models

Public cloud, EU hosting, private cloud, on-premise LLM or hybrid?

No model is universally best. The right choice depends on protection needs, required models, hardware, latency, operations, integrations, updateability, scaling and cost structure.

Public Cloud

Managed AI with broad model access

Useful when rapid availability and current models matter more than maximum infrastructure control and the chosen service fits the data, contracts and use case.

  • Fast start and low in-house operational workload
  • Broad access to capable models and services
  • Review provider contracts, data processing, roles and logging
  • Plan for variable cost and provider dependency
EU Hosting

AI in a European hosting and contractual framework

Can be sufficient when processing in a suitable EU environment with appropriate technical and contractual measures meets the protection need.

  • Less own hardware than full on-premise operation
  • Define regional data processing technically and contractually
  • Managed or self-managed open-source stacks are possible
  • Subprocessors, support paths and model access still require review
Private Cloud

Dedicated environment with stronger network and access control

Useful when isolated environments, private networks and controlled administration are needed but owning hardware is not.

  • Stronger isolation and custom network boundaries
  • Integrate own identity, logging and permission concepts
  • Split operational responsibility clearly by managed-service model
  • More control, but also more architecture and operations work
On-Premise LLM

Local AI on your own infrastructure

Useful for high protection needs, offline requirements, very low latency or when data and model access should deliberately remain under full infrastructure control.

  • Maximum control over infrastructure, models and network access
  • GPU, memory and capacity planning become architecture concerns
  • Updates, monitoring, backups and security shift toward your own operations
  • Not every model or load profile is economical to run locally
Hybrid AI

Route workloads by sensitivity and model need

Useful when sensitive processing should stay local or private while other tasks may intentionally use more capable external models.

  • Controlled separation by data class and use case
  • Local and external models can be combined deliberately
  • Routing, policy enforcement and observability become more important
  • More flexibility with higher architecture complexity

Guiding principle: choose the smallest architecture that cleanly satisfies data, risk, operations and business requirements. On-premise is not an end in itself; public cloud is not automatically disqualified.

An existing on-premise example is meeting AI: transcription and analysis can run locally while source attribution and traceable results remain part of the workflow.

Decision criteria

What needs to be clear before choosing an operating model.

Sovereignty here means controllable technical and organisational decisions, not a blanket compliance promise. These four areas determine how much infrastructure control is actually useful.

Data & protection needs

Data classes, permitted processing locations, tenant separation and roles determine whether public cloud, EU hosting, private cloud or on-premise is viable.

Models, latency & scaling

Required model quality, context size, response time, volume and offline requirements help determine cloud access, own hardware or a hybrid solution.

Operations, updates & integrations

Hardware, monitoring, patching, model updates, backups and interfaces must remain operable over time, not only work in a demo.

Portability & cost structure

API dependencies, data formats, model switching, exit path plus fixed and variable costs are planned so lock-in remains a conscious trade-off.

Approach

Decide independently, then implement deliberately.

I do not sell a particular model or hosting model. The architecture is derived from business requirements, data, risk, integrations and operability.

Where a simple managed service is sufficient, running GPUs yourself is unnecessary. Where data, latency, offline capability or control boundaries require it, private cloud, on-premise or hybrid can be the better choice.

Implementation path

From inventory to controlled AI operations.

Phase 1

Sovereignty check

AI stocktaking in one week.

We capture current AI use, data flows, protection needs, existing infrastructure and the processes where controlled AI can create genuine value.

  • Documented AI and data inventory as a technical working basis
  • Assessment of critical data flows and control boundaries
  • Prioritised use-case list with technical effort assessment
  • Recommendation for public cloud, EU hosting, private cloud, on-premise or hybrid
Duration
approx. 1 week
Investment
from €1,490
Phase 2

Controlled AI foundation

A private AI workplace with the appropriate operating model.

Based on the decision, a usable AI foundation is built – EU-hosted, private cloud, on-premise or hybrid – plus one bounded workflow connected to existing systems and data.

  • Operating model and data paths matched to the agreed protection need
  • One integrated business process as a concrete starting point
  • Short practical team onboarding as a contribution to AI literacy under Article 4
  • Documented setup with portable components where practical and clear responsibilities
Duration
approx. 4 weeks
Investment
from €9,900
Phase 3

AI operations

Keep models, integrations and controls current.

Optionally I support updates, additional workflows, model changes and technical adjustments. Architecture and configuration remain traceable so no unnecessary operational lock-in is created.

  • Regular technical maintenance and updates
  • Extension with further workflows based on real needs
  • Occasional sparring for business units, IT and management
Duration
cancellable monthly
Investment
from €1,200 per month
Quick entry point

The Shadow AI Check

If it is unclear which AI tools are already in use and where data flows, the compact check creates a solid starting point for architecture and governance decisions within 2–3 days.

Scope: the Check is a technical and organisational inventory with an immediate recommendation, not a legal assessment. The deeper review with a prioritised use-case list comes with the Sovereignty Check (Phase 1); the Check fee is credited toward continued work.

What you get
  • Inventory of AI tools in use – including unofficial shadow AI
  • Overview of relevant data flows and external processing paths
  • Traffic-light classification as a working basis for an internal AI policy
  • Technical framing of GDPR and EU AI Act requirements, clearly separated from legal advice
  • Concrete immediate recommendation and next technical step
Duration
2–3 days
Investment
from €890
Real experience

Self-hosted LLMs, RAG, agents and permission separation in use.

The experdoo reference documents a fully self-hosted AI architecture with RAG for internal knowledge, multiple agents and clear tenant, data and permission separation. The reference page also describes productive use.

Thomas understood the complex project quickly, communicated clearly and delivered reliably. This mix of technical understanding and professional collaboration makes the difference.

Martin Guntermann, Managing Director · experdoo GmbH

Next paths

Decide the architecture, integrate it and control existing usage.

Depending on the starting point, the biggest lever may be an architecture decision, concrete integration or visibility into existing shadow AI rather than more infrastructure.

AI architecture consulting

When hosting is only one part of a broader target architecture with data flows, system boundaries and integrations.

AI integration

When the operating model is decided and AI should be integrated into existing ERP, CRM, DMS or line-of-business workflows.

Frequently asked questions

Answers without blanket hosting promises.

Is private AI automatically GDPR-compliant?

No. The operating model can support data minimisation, access control and controlled processing, but it does not replace assessment of the concrete purpose, roles, contracts, legal bases and technical measures. I account for GDPR requirements technically; this is not legal advice.

Does my data really stay there with EU hosting or on-premise?

It depends on the concrete setup. With on-premise, model processing and data storage can be designed to remain fully local; with EU hosting, region, subprocessors, support and telemetry paths plus contractual commitments need to be checked. That is why I avoid blanket location promises without architecture and provider review.

Which EU AI Act obligations already apply?

AI literacy measures under Article 4 have applied since 2 February 2025. Article 50 transparency obligations have applied since 2 August 2026. Which duties apply in a particular case depends, among other things, on role, system and use. This technical framing does not replace legal advice.

Public cloud, EU cloud or on-premise – which is better?

None of them universally. For low-sensitivity workloads, public cloud can minimise operational effort. EU hosting or private cloud can increase control depending on setup. On-premise is justified when protection needs, offline capability, latency or infrastructure control warrant the additional operations. Hybrid is useful when different workloads need different boundaries.

What happens to the tools we already use?

Existing tools are not replaced blindly. We review data flows, contracts, integrations and actual value and then decide what stays, is secured, is replaced or belongs in a hybrid architecture.

What does the introduction cost?

The existing entry packages remain transparent: the Shadow AI Check starts from €890, the Sovereignty Check from €1,490 and the AI foundation from €9,900. The concrete scope depends on the operating model and existing systems.

Next step

Which operating model does your AI use case actually need?

Describe the data, existing systems and planned AI workflow. I will assess whether public cloud, EU hosting, private cloud, on-premise or hybrid is the smallest defensible path.