Reading time: about 9 minutes
Most AI workloads in a manufacturing company can sit comfortably in public cloud, and should. Only a minority needs a sovereign, on-prem deployment: the workloads where the model touches your intellectual property, data covered by NIS2 or GDPR, or data a customer will ask about in a supplier audit. Accenture puts that minority at 36%. The decision rule is simple: you are not asking "cloud or on-prem", you are asking "which specific data cannot leave the perimeter". Below is a table that maps a manufacturer's typical workloads to one of two answers, plus a four-question test to classify your own case in minutes.
What the Accenture study actually found
For two years "sovereign AI" sounded like a conference slogan. Something you discuss on a panel, then go back to using whatever ships fastest. In 2026 that picture stopped matching the data.
Accenture surveyed 1,928 organizations across 28 countries. The result: 62% of the European organizations surveyed report a greater propensity to reach for sovereign solutions under geopolitical uncertainty (Accenture, fieldwork July and August 2025). In Germany, which for a Polish manufacturer is most often the first export customer, that figure reaches 72%. In Denmark, 80%. And 60% of European organizations say they will increase investment in this category over the next two years.
Read the number carefully, because it gets misused. It is a level, not a trend: the study is a single measurement with no year-on-year comparison, and the full report notes that every respondent came from an organization that already treats sovereignty as highly or critically important. So 62% does not mean "62% of all European firms", it means "62% among those who already take the topic seriously". The level is what matters, because it describes the room you are selling into today.
What changed the buyer's calculation
Not the technology. Public models are better today than a year ago. What changed is the buyer's risk calculation, and it changed for three reasons at once.
Regulation stopped being theoretical. The NIS2 rollout placed accountability for supply-chain security on management boards, and an AI vendor that ingests your data is part of that chain. This is no longer an IT problem, it is a line the board is personally answerable for, and one that gets validated up and down the supply chain.
A policy ban proved insufficient. A run of public data leaks into cloud tools showed that a rule in a handbook does not protect you, because an employee still pastes a drawing or a BOM into a public chat to finish a task faster. The data ends up outside the perimeter despite the ban.
Vendor lock-in started getting costed in money. Companies worked out what it really means to hand drawings, offers, and documentation to a single provider that processes them, and sometimes trains on them. Sovereignty stopped being an ideological pose. It became a line item on the risk register.
Sovereign does not mean "everything in-house"
Here is the nuance that gets lost in the slogans. The same report shows that only 36% of AI initiatives in European organizations actually require a sovereign approach. The rest can stay in public cloud.
That matters, because "sovereign AI for everything" is a road to nowhere: more expensive, slower, pointless for handling email or generating marketing graphics. Full on-prem for a workload that only ever touches public data is cost with no matching risk. The opposite mistake is worse, though: dropping technical documentation into a public model because "everyone does it". So the question is not "cloud or on-prem", it is "which specific processes cannot leave the perimeter, and which can and should stay in it".
Decision table: which workloads stay in cloud, which do not
For a manufacturer the answer is usually more precise than it looks. Below are typical workloads ranked by data sensitivity and regulatory exposure.
| Workload / data | Sensitivity and regulatory exposure | Verdict | Action |
|---|---|---|---|
| Technical documentation, manuals, drawings | High: IP, trade secrets | Sovereign / on-prem | RAG on your own infrastructure |
| Service ticket history, machine data | High: customer and operational data | Sovereign / on-prem | On-prem deployment |
| Offers, quotes, costings | High: commercial data | Sovereign / on-prem | On-prem deployment |
| Personal data and data inside a NIS2 chain | High: GDPR plus NIS2 | Sovereign / on-prem | On-prem deployment |
| General email correspondence | Medium: depends on content | Depends on content | Classify case by case |
| Marketing graphics, public content | Low | Public cloud | Stays in the cloud |
| Research from public sources | Low | Public cloud | Stays in the cloud |
The pattern is clear: workloads that feed AI your intellectual property and regulated data are candidates for a sovereign deployment. Workloads that operate on already-public content stay in the cloud, because there is nothing to protect.
The classification test: four questions
If you do not want to map every process at once, four questions settle a single case. One "yes" is enough to treat a workload as a sovereign or on-prem candidate.
First: does this data contain intellectual property, trade secrets, or information whose leak would hit your customer? Second: is the process subject to NIS2, GDPR, or a contractual data-location clause? Third: is this data an edge you would be handing to a model that learns on other people's prompts? Fourth: will a customer, say a German OEM, ask in a supplier audit where this data is processed?
Four "no" answers mean the workload stays in the cloud. A single "yes" moves it inside the perimeter.
Classifying workloads: public data stays in the cloud, sensitive data moves inside the perimeter.
The Polish angle: the German supply chain
For a Polish manufacturer this trend has an extra layer. The first serious customer is often a buyer in Germany, where the expectation of sovereignty is already high and rising (72% in the Accenture study). If your company wants to be a supplier inside a German supply chain covered by NIS2, the way you process data stops being your internal affair. It becomes part of how you are assessed as a vendor, because your customer answers to the regulator for the security of the whole chain and will validate that downstream, at you.
In other words: a sovereign AI deployment is not only protection ahead of your own audit. It is a sales argument toward customers who are under the same pressure. Increasingly it is not you asking whether it is worth it, it is the customer asking how you have it set up.
What to do about it, concretely
Start with a map, not with technology. List the AI workloads you already run or plan, and run each through the four-question test. Usually most stay in the cloud, and a short list emerges of workloads that touch technical documentation, service history, and offers, and those go to the perimeter.
For that short list, work out what "cannot leave" actually means: GDPR, NIS2, a customer's contractual clause, or the raw value of the IP. That determines how strong the isolation needs to be and what you will have to show in an audit. Only then choose the architecture, because only then do you know what problem it has to solve.
We built CortexMine for exactly those 36% of workloads that cannot leave the perimeter. A private AI platform for European manufacturers, deployed on-prem: data never leaves your infrastructure, every answer is grounded in your own sources, and the whole thing leaves an audit trail you can put in front of an auditor. We do not claim everything should be sovereign. We claim the workloads where you handle drawings, offers, and technical documentation should be.
If you want to check your own list, start with the readiness mini-audit: it takes 10 minutes and leaves no data behind. For the architectural background, read On-prem AI in manufacturing: when it fits, and when it doesn't.
Frequently asked questions
Are "sovereign AI" and "on-prem AI" the same thing?
Not quite. Sovereignty is a business and legal requirement: your data and model stay under your control and jurisdiction. On-prem is one way to achieve it, alongside private cloud or a deployment in a sovereign data center in-country. For most manufacturers on-prem is the simplest way to prove control in an audit.
Where does the 36% come from?
From Accenture's 2025 "Sovereign AI" report: that share of AI initiatives in the surveyed European organizations requires, per respondents, a sovereign approach. It is a rough magnitude, not your specific result. Your result only comes from a process map run through the four-question test.
Do I have to move the whole company on-prem?
No. Only the short list of workloads that touch sensitive data is worth it. The rest, from email to marketing graphics, stays in the cloud, because moving it raises cost without reducing risk.
Why would my German customer ask about this?
Because NIS2 placed accountability for supply-chain security on their board, and you are in that chain. How you process their data in AI tools becomes part of how you are assessed as a supplier.
Where do I start with no AI team?
With a process map and the four-question test, not with buying infrastructure. Only the short list of sovereign workloads tells you what architecture you need. The readiness mini-audit walks you through it step by step.
