Reading time: about 8 minutes
There is no single right answer between single-tenant cloud and shared cloud: the model follows the data. Shared cloud is the right call for a smaller company still testing whether AI helps, on low-sensitivity data and outside a hard audit. Single-tenant cloud, a dedicated instance that is yours alone, is the right call when production data cannot share an environment with anyone else, when a NIS2 audit is in play, or when you need firm control over what changes and when. The rest of this guide is a map for telling which of the two situations is yours, with a decision table you can run against your own case in a couple of minutes.
We leave on-prem aside here, since owning hardware is a separate conversation. This is a choice inside the cloud: a shared instance versus a dedicated, isolated one that is yours alone.
What separates shared cloud from single-tenant cloud
Both models run in the cloud. The difference is who you share the environment with, and how the separation between customers is enforced.
- Shared cloud (multi-tenant): one instance serves many customers at once. Your data is logically separated, but it physically shares the same infrastructure, the same compute, and often the same model. The isolation is enforced in software, not by a physical boundary.
- Single-tenant cloud (dedicated instance): you get a separate, isolated environment for yourself. No one else shares your resources. The data still physically lives with the infrastructure provider, but the environment is yours and only yours.
This is not a marketing distinction. As Microsoft's own guidance on secure isolation spells out, a multi-tenant cloud keeps customers apart with logical controls in software rather than a dedicated physical boundary, which is exactly the line a single-tenant deployment moves. That difference shows up in three concrete places: when you answer an auditor's question, at the boundary of data you are not allowed to release, and in control over what changes in the environment and when.
When shared cloud is the right call
Despite what some vendors imply, shared cloud is not the "lite" version. For many companies it is exactly where you should start.
- You are still testing whether AI helps at all. If you are at one workflow and one team, shared cloud starts fastest and does not tie up budget in a dedicated environment before you know the value.
- The data is low-sensitivity. Marketing content, general documentation, material that already is or could be public. Here isolation buys you no real protection, just cost and setup time.
- You are not under a hard audit. If you are neither a key nor an important entity under NIS2 and no contract forces a dedicated environment, shared cloud meets the bar without overbuilding.
- Entry barrier and speed matter. A smaller team, a limited budget, results needed in weeks. Shared cloud gives you the lowest barrier to start and the shortest path to a first result.
For a company under roughly 50 people testing a first use case on low-sensitivity data, shared cloud is not a compromise. It is the right decision, and moving to a dedicated environment before any of the signals below appear is paying for security you do not yet need.
When single-tenant cloud starts to make sense
Single-tenant comes into play when several of these signals show up together, not just one on its own.
- Production data that cannot be shared. Technical drawings, formulations, process documentation, data under NDAs. If the mere fact of sharing an environment breaches a contract or an internal policy, isolation stops being optional and becomes the baseline.
- A NIS2 audit asking about the data boundary. Manufacturing usually lands in the important (ważny) category under NIS2, and some firms in the key (kluczowy) one, with the same Article 21 obligations for both. In Poland the amended national cybersecurity act (KSC) opened a self-registration window running from 7 May to 3 October 2026, after which covered entities are entered in the register of key and important entities, as KPMG's Poland alert sets out. An auditor will ask exactly where data is processed and who can reach it, and "a dedicated environment, only ours, with documented isolation" is far easier to defend than "logical separation inside a shared instance".
- Supply-chain scrutiny that reaches your AI vendor. NIS2 pushes covered entities to assess the security of their ICT supply chain and their dependence on external providers, a point Schoenherr's analysis of the Polish implementation underlines. Your AI tool's deployment model is part of that assessment, and a shared instance is one more third-party dependency you have to account for.
- You need control over the change cycle. In shared cloud, provider-side changes hit everyone at once. Single-tenant lets you decide when and what changes in your environment, test a new model version on your data first, or pin a version while stability matters more than novelty.
- Volume and horizon already justify it. Once AI becomes a daily tool rather than an experiment, a dedicated environment stops being overbuild and starts being predictability.
Decision table: which model fits your case
The fastest way to decide is to line up your real situation against the data that goes into the model, and read off the model and the first step.
| Your situation | Data going in | Model that fits | First step |
|---|---|---|---|
| Small team, first pilot, one workflow | Low-sensitivity, could be public | Shared cloud | Start on that one workflow, revisit at scale |
| Drawings, BOMs, formulations in the workflow | Intellectual property | Single-tenant cloud | Scope the isolation boundary before go-live |
| Key or important entity, data in scope of an audit | Regulated under NIS2 | Single-tenant cloud | Document the boundary for the auditor |
| Customer or partner data under NDA | Contractually restricted | Single-tenant cloud | Check the environment-sharing clause first |
| Daily tool, several teams, multi-year horizon | Mixed, heavy use | Single-tenant cloud | Move off shared once volume justifies it |
| Occasional questions, learning a tool | No company data | Shared cloud | Do not overbuild, isolation adds nothing |
The pattern is the same one that runs through the whole decision: what tips you toward single-tenant is not the industry or the size of the company, it is the sensitivity of the data at the input in one specific use.
Shared cloud separates customers in software; single-tenant gives each one a dedicated boundary.
How they look side by side
Reduced to the dimensions that actually drive the choice, the two models line up like this.
- Isolation: shared is logical, software-level. Single-tenant is a full, separate environment that is yours alone.
- Entry barrier: shared is low, single-tenant higher.
- Defending it to an auditor: shared needs you to explain the separation mechanism. Single-tenant answers in one sentence.
- Control over changes: shared sits with the provider. Single-tenant sits with you.
- Who it is for: shared for smaller teams, testing, low-sensitivity data. Single-tenant for regulated work, on data that cannot share an environment.
If you want the level below this comparison, how a dedicated instance is actually isolated, what an auditor sees and where a "single-tenant" setup still leaks, we take that apart in the piece on how single-tenant isolation works in practice.
A four-step way to decide
- Map the data sensitivity in this one workflow. Not the whole company, just what actually goes into the model. If it is data that could be public, shared is enough.
- Check your regulatory status. Being a key or important entity under NIS2 raises the weight of dedicated isolation, and the Polish registration window closes on 3 October 2026.
- Ask what you would tell the auditor. If "logical separation" satisfies you, shared is fine. If you need a hard boundary you can point to, that is a signal for single-tenant.
- Weigh the horizon. A quarter-long experiment versus a tool for years. The longer and heavier the use, the stronger the case for a dedicated environment.
For many mid-sized manufacturers the honest path is this: start with shared cloud on a single low-sensitivity workflow, and reach for single-tenant once data, regulation and scale point the same way. For NIS2-covered entities working on documentation that cannot be shared, single-tenant can be the right call from the start. If you are still deciding whether you need a private environment at all, the earlier question of private versus public AI for manufacturing comes first.
The quickest way to place your own case is our readiness mini-audit: it takes 10 minutes, leaves no data behind, and shows which side of the line your uses fall on.
Frequently asked questions
What is the difference between single-tenant cloud and shared cloud?
Both run in the cloud. Shared cloud (multi-tenant) serves many customers from one instance with logical, software-level separation. Single-tenant cloud gives you a dedicated, isolated instance that no one else shares, which is easier to defend when the data is sensitive.
Is shared cloud less secure than single-tenant?
Not automatically. For low-sensitivity data and outside a hard audit, logical separation is enough and single-tenant adds cost without adding protection. The difference matters once production data or a regulator is involved.
Which model does NIS2 require?
NIS2 does not name a deployment model. It asks you to control and document where data is processed and to assess your supply chain. Single-tenant makes that answer simpler, because the data boundary defends itself in one sentence.
Can we start on shared cloud and move to single-tenant later?
Yes, and for many companies that is the right sequence: prove the value on a low-sensitivity workflow in shared cloud, then move to a dedicated environment once data, regulation or scale justify it.
Is single-tenant cloud the same as on-prem?
No. Single-tenant is still a dedicated instance at an infrastructure provider. On-prem means the model and data run on your own hardware. That is a separate decision, once you already know you need isolation.
Fryderyk, CortexMine. We write about private AI for NIS2-covered manufacturers, based on our own deployments and tests.
Prefer to talk it through? Book a 30-minute call with the founder, no pitch, just your case.
