Data & protection needs
Which information may be processed in which environment? Personal, confidential or regulated data needs different guardrails from public content.
GDPR requirements, confidential company data and AI workloads need controllable data flows – but not automatically your own server. The key is an operating model that balances protection needs, models, integrations, cost and operations.
I design and implement sovereign AI architectures without vendor dogma: public cloud, EU-hosted AI, private cloud, local AI on your own infrastructure or hybrid AI. Privacy and GDPR requirements are engineered into the design without pretending self-hosting automatically creates compliance. The goal is the smallest controllable architecture without unnecessary vendor lock-in.
A “private LLM” can have very different control boundaries depending on provider and setup. A sound decision has to consider data location, contracts, model access, network, permissions, hardware, updates, scaling and integrations together.
Which information may be processed in which environment? Personal, confidential or regulated data needs different guardrails from public content.
A local model increases infrastructure control but adds hardware, update and operational work. Managed cloud can be faster when the protection need permits it.
AI literacy measures under Article 4 have applied since 2 February 2025. Article 50 transparency obligations have applied since 2 August 2026, depending on role and system. Technical architecture does not replace case-specific legal assessment.
The useful answer is therefore not “cloud bad, on-prem good”, but an operating model whose control level fits the workload and can actually be operated day to day.
No model is universally best. The right choice depends on protection needs, required models, hardware, latency, operations, integrations, updateability, scaling and cost structure.
Useful when rapid availability and current models matter more than maximum infrastructure control and the chosen service fits the data, contracts and use case.
Can be sufficient when processing in a suitable EU environment with appropriate technical and contractual measures meets the protection need.
Useful when isolated environments, private networks and controlled administration are needed but owning hardware is not.
Useful for high protection needs, offline requirements, very low latency or when data and model access should deliberately remain under full infrastructure control.
Useful when sensitive processing should stay local or private while other tasks may intentionally use more capable external models.
Guiding principle: choose the smallest architecture that cleanly satisfies data, risk, operations and business requirements. On-premise is not an end in itself; public cloud is not automatically disqualified.
An existing on-premise example is meeting AI: transcription and analysis can run locally while source attribution and traceable results remain part of the workflow.
Sovereignty here means controllable technical and organisational decisions, not a blanket compliance promise. These four areas determine how much infrastructure control is actually useful.
Data classes, permitted processing locations, tenant separation and roles determine whether public cloud, EU hosting, private cloud or on-premise is viable.
Required model quality, context size, response time, volume and offline requirements help determine cloud access, own hardware or a hybrid solution.
Hardware, monitoring, patching, model updates, backups and interfaces must remain operable over time, not only work in a demo.
API dependencies, data formats, model switching, exit path plus fixed and variable costs are planned so lock-in remains a conscious trade-off.
I do not sell a particular model or hosting model. The architecture is derived from business requirements, data, risk, integrations and operability.
Where a simple managed service is sufficient, running GPUs yourself is unnecessary. Where data, latency, offline capability or control boundaries require it, private cloud, on-premise or hybrid can be the better choice.
AI stocktaking in one week.
We capture current AI use, data flows, protection needs, existing infrastructure and the processes where controlled AI can create genuine value.
A private AI workplace with the appropriate operating model.
Based on the decision, a usable AI foundation is built – EU-hosted, private cloud, on-premise or hybrid – plus one bounded workflow connected to existing systems and data.
Keep models, integrations and controls current.
Optionally I support updates, additional workflows, model changes and technical adjustments. Architecture and configuration remain traceable so no unnecessary operational lock-in is created.
If it is unclear which AI tools are already in use and where data flows, the compact check creates a solid starting point for architecture and governance decisions within 2–3 days.
Scope: the Check is a technical and organisational inventory with an immediate recommendation, not a legal assessment. The deeper review with a prioritised use-case list comes with the Sovereignty Check (Phase 1); the Check fee is credited toward continued work.
The experdoo reference documents a fully self-hosted AI architecture with RAG for internal knowledge, multiple agents and clear tenant, data and permission separation. The reference page also describes productive use.
Thomas understood the complex project quickly, communicated clearly and delivered reliably. This mix of technical understanding and professional collaboration makes the difference.
Martin Guntermann, Managing Director · experdoo GmbH
Depending on the starting point, the biggest lever may be an architecture decision, concrete integration or visibility into existing shadow AI rather than more infrastructure.
When hosting is only one part of a broader target architecture with data flows, system boundaries and integrations.
When the operating model is decided and AI should be integrated into existing ERP, CRM, DMS or line-of-business workflows.
No. The operating model can support data minimisation, access control and controlled processing, but it does not replace assessment of the concrete purpose, roles, contracts, legal bases and technical measures. I account for GDPR requirements technically; this is not legal advice.
It depends on the concrete setup. With on-premise, model processing and data storage can be designed to remain fully local; with EU hosting, region, subprocessors, support and telemetry paths plus contractual commitments need to be checked. That is why I avoid blanket location promises without architecture and provider review.
AI literacy measures under Article 4 have applied since 2 February 2025. Article 50 transparency obligations have applied since 2 August 2026. Which duties apply in a particular case depends, among other things, on role, system and use. This technical framing does not replace legal advice.
None of them universally. For low-sensitivity workloads, public cloud can minimise operational effort. EU hosting or private cloud can increase control depending on setup. On-premise is justified when protection needs, offline capability, latency or infrastructure control warrant the additional operations. Hybrid is useful when different workloads need different boundaries.
Existing tools are not replaced blindly. We review data flows, contracts, integrations and actual value and then decide what stays, is secured, is replaced or belongs in a hybrid architecture.
The existing entry packages remain transparent: the Shadow AI Check starts from €890, the Sovereignty Check from €1,490 and the AI foundation from €9,900. The concrete scope depends on the operating model and existing systems.
Describe the data, existing systems and planned AI workflow. I will assess whether public cloud, EU hosting, private cloud, on-premise or hybrid is the smallest defensible path.