Sovereign AI Begins With What You Will Not Outsource
Some AI work is safe to hand to a vendor. The work that makes your company what it is calls for a different answer.
Sovereign AI is a company taking responsibility for its own intelligence. It means the AI that touches your proprietary knowledge, your confidential data, and your critical decisions runs under your control, on infrastructure you govern, with people in your company accountable for what it does. Controlling the hardware is part of it. The larger part is accepting a responsibility that is easy to hand to an AI vendor without noticing.
Every business already draws this line in other parts of its operation. A company may outsource payroll processing, facilities, or its help desk with little hesitation. It is far less likely to outsource its pricing strategy, its product formulations, or its relationships with its best customers. Those are the things that make the business what it is, and leadership treats them as its own responsibility.
AI has blurred that line. A single tool can draft a routine email in the morning and analyze your margin by customer in the afternoon, and the same terms of service govern both. The question sovereign AI asks is simple: which of those capabilities are you willing to place in someone else's hands?
What is sovereign AI?
Sovereign AI is artificial intelligence that a company controls and takes responsibility for, from the infrastructure it runs on to the knowledge it accumulates and the decisions it is allowed to make.
The term began with nations. Governments have committed enormous sums to keep their AI capabilities under their own control, which I wrote about in the sovereign AI operating system. The same reasoning applies to a company, because a company's advantage also lives in what it knows.
For a business, that responsibility covers four areas. The first is where the AI runs: the everyday models operate on systems you control and can account for. The second is the data it touches: your information is processed inside your boundary, and you can say with certainty where it went and who retained it. The third is what the AI learns: your methods, your standard answers, and the reasoning behind your decisions accumulate inside your company and remain there when people leave. The fourth is what the AI may decide: your policies apply on every task, a person approves the work, and the system records what happened.
When a vendor holds any of those four, it holds part of the responsibility, and with it part of your control.
Sovereignty is not just about owning. It is about taking responsibility.
Which AI capabilities should a company keep under its own control?
A company should keep three kinds of AI capability under its own control: anything proprietary, anything confidential, and anything critical to how the business runs.
Proprietary capabilities are the ones that make you different. Your pricing logic, your process know-how, the way you qualify a customer or resolve a quality issue. C.K. Prahalad and Gary Hamel described this in 1990 as core competence, the collective learning of an organization that competitors find difficult to imitate1. When an AI system learns your core competence, the system itself becomes part of it. Placing that learning outside your walls means placing a piece of your advantage there too.
Confidential capabilities are the ones that handle information you are obligated to protect: customer records, employee data, contract terms, financials. Here the responsibility is not optional. Your customers and employees entrusted that information to you, and an AI vendor's retention policy does not change who answers for it. I walked through where that data can travel, and what a vendor may still do with it, in does AI train on your data.
Critical capabilities are the ones your operation depends on day to day, such as scheduling, quoting, inventory, and service. If an outside provider changes its terms, its pricing, or its model, a critical capability should not change with it unless you decide it should.
Everything else is a candidate for outsourcing, and there is plenty of it.
What can a company safely outsource?
A company can safely outsource AI work that is general, occasional, and touches nothing proprietary, confidential, or critical.
General-purpose tools are good at that work. When someone needs to draft a routine email, summarize a public article, or brainstorm a first outline, a hosted assistant is fast, inexpensive, and needs no setup. The same holds for the occasional hard problem that calls for the most capable frontier model available, provided the task is sent under terms you have chosen, such as zero data retention.
Outsourcing responsibly also means knowing which plan your people are on, because the privacy terms change sharply by tier. On the consumer plans, including the paid individual ones, conversations can be used to train future models unless the user turns that setting off. Anthropic, for example, trains on Free, Pro, and Max accounts when the setting is on and keeps that data for up to five years2. The business plans from the major vendors do not train on your data by default, but they still retain it for a period, and authorized staff or contractors can review it for abuse3. The controls that let a company decide how long its data is kept, such as OpenAI's custom retention setting, sit on the enterprise tier3.
That tier is a different purchase. ChatGPT Business lists at $20 per user per month. ChatGPT Enterprise is sold by quote, and procurement reports put it around $60 per user with a minimum near 150 seats, roughly $108,000 a year before anyone logs in4. For a 20-person company on the business plan, that is more than twenty times the annual cost. Buying that level of protection is the price of outsourcing confidential work responsibly, and for a smaller company it is a strong argument for keeping that work under its own control.
Keeping critical work under your control costs less capability than it once did. Since January 2026, the most capable open-weight models, the kind a company can run on its own systems, have trailed the frontier by an average of about four months on Epoch AI's capabilities index5. For the everyday work of a business, a capable model that operates under the company's rules matters more than the newest release.
What does taking responsibility for AI require?
Taking responsibility for AI requires three things: infrastructure you control, a platform that holds your company's knowledge and rules, and a short onboarding that connects it to the systems you already run.
The infrastructure is now within reach of a small company. A Mac Studio, an NVIDIA DGX Spark, or an AMD Ryzen AI system will run a very large model for a few thousand dollars and fits on a shelf. I covered the hardware options in more detail in my piece on running AI on hardware you control.
The platform is what makes that hardware useful. It manages the connections to your other systems, the security and role controls, the institutional memory, and the coordination that lets the pieces work together.
Onboarding happens in three steps: install, ingest, integrate. You install the platform on your infrastructure. You ingest your business content, the documents, playbooks, and knowledge that currently live in people's heads and scattered drives. Then you integrate the systems your team already uses, such as email, chat, your ERP, and your CRM. Plan on one to two weeks, depending on how much content you bring in and how many systems you connect. Your team keeps working in familiar tools, and the AI works behind them, the approach I described in the best AI in your company will not have a screen.
Through all of it, one rule carries the responsibility: the AI recommends and prepares the work, a person approves it, and the system records what happened.
What does sovereign AI cost?
Sovereign AI has three costs: hardware you buy once, a platform you pay for monthly, and onboarding you pay for once.
The hardware runs roughly $4,000 to $10,000 today, depending on the workload. Because the compute is yours, there is no per-token charge when your team relies on the system all day, and the cost does not rise when you add a person.
The platform is the recurring cost, and vendors price it in different ways. I would favor pricing tied to the size of your business over pricing tied to the number of users, because the value of AI under your control shows up across the organization rather than one person at a time.
For comparison, Microsoft 365 Copilot Business lists at $21 per user per month on a yearly plan6. At 50 people that is $12,600 a year, and at 200 it is $50,400. Getting started with sovereign AI costs more than a single seat. Over the following years the comparison shifts, because per-user costs climb with every hire while the knowledge your own system maintains deepens every month. If you want the early results to fund the later ones, I wrote about structuring that in make your AI program pay for itself.
Where should a company start with sovereign AI?
Start by sorting the AI work your company already does into two groups: the work that is proprietary, confidential, or critical, and the work that is not.
The inventory can often be done in an afternoon. In my experience it turns up AI already touching sensitive work through tools no one formally approved. The first sovereign capability to build is the most important item in the first group.
From there, start small but connected. Bring one capability under your control at a time, on a single platform, so each addition strengthens the ones already running. Some value arrives in the first week, such as a single view across your systems and a morning brief of what happened overnight. Other value takes longer to develop, such as policies refined through real exceptions, or advice that weighs a decision against your objectives and procedures. Plan on roughly a quarter for the system to know your business well.
Is sovereign AI realistic for a small or midsize company?
Yes, and a smaller company is often better positioned to take this responsibility than a large one.
A smaller company has fewer systems to connect, fewer layers between a decision and the person accountable for it, and less legacy process to unwind, which is the argument in small and midsize businesses can adopt AI faster than the enterprise. The infrastructure that once required a data center now costs a few thousand dollars.
Large institutions are already doing it. America's oldest bank chose to build its own AI platform, and the order it followed scales down well, as I wrote in what BNY's build teaches a business your size.
Proxigee Services is an AI advisory firm in the Pittsburgh area that helps small and midsize companies decide which AI capabilities to keep under their control, which to outsource, and where to begin.
A vendor can run your tools. Only your company can be responsible for what it knows.
Which of your AI capabilities should stay in-house?
Proxigee Services helps small and midsize companies sort what is proprietary, confidential, and critical from what is safe to outsource, then bring the first critical capability under their control.
Schedule a conversation →Sources referenced
- C.K. Prahalad and Gary Hamel, "The Core Competence of the Corporation", Harvard Business Review, May 1990. ↩
- Anthropic, "Updates to Consumer Terms and Privacy Policy", August 28, 2025, on training with Free, Pro, and Max data and five-year retention when the setting is on. ↩
- OpenAI, "Managing data, sharing, and privacy in ChatGPT Business", and "Enterprise privacy at OpenAI," on business data excluded from training by default, abuse review, and Enterprise custom retention. ↩
- Coworker, "ChatGPT Enterprise Pricing in 2026", updated September 30, 2026, on reported Enterprise pricing and seat minimums, which OpenAI does not publish; ChatGPT Business list price per Elephas, "ChatGPT Business, Team, and Enterprise Pricing," 2026. ↩
- Epoch AI, "Open models lag state-of-the-art closed models by 4 months", May 29, 2026. ↩
- Microsoft, "Microsoft 365 Copilot Business" plans and pricing, accessed September 2026. ↩
Terry D. Lyon is the founder of Proxigee Services, a Pittsburgh-based advisory firm helping small and midsize companies navigate the current AI innovation cycle with focus on agentic use cases, the right first projects, and building Intelligence Estates that compound in value over time.