The move to local and open-weight models has stopped being a niche position. At this month’s RAISE Summit the pattern was named out loud: enterprises are shifting AI workloads toward open-weight models to regain control over their data[1]. The reasons are not ideological. They are the three questions every European leadership team is currently asking us: does the EU AI Act change our deployment maths, is our data actually safer, and what is genuinely cheaper. Good questions. The honest answers are more conditional than either camp admits.

Why the move is real
The capability argument against open models has largely collapsed. Moonshot’s Kimi K2 crossed the trillion-parameter threshold as an open-weight model in mid-2025, and the current generation of open leaders trails frontier closed models by roughly three months on capability, a gap that keeps shrinking[1]. The market has already voted with its architecture: a survey of 145 enterprises found 51 percent blending closed frontier models with open-weight models on their own infrastructure, and another 16 percent moving core workflows off closed APIs entirely[2]. After June’s Fable 5 outage demonstrated what a single external restriction can do to a closed-only setup, nobody needs the dependency argument explained twice.

The three checks we run before any local move
One: technical readiness, on site. A trillion-parameter open model is not a download, it is an operations commitment. Before any migration we ask the unglamorous questions: is the GPU capacity real or planned, who patches and evaluates the model, who owns uptime at 2am, and does the team that runs your ERP have the skills to run inference infrastructure. If the honest answer is no, a managed EU-hosted deployment beats a server room fantasy.
Two: the data protection assessment. Local deployment makes one thing unambiguous: your prompts and your context never leave your perimeter. For regulated industries and for anyone taking the EU AI Act seriously, that clarity has real value: transparency obligations apply from 2 August 2026 regardless of where your model runs[3]. But local is not automatically compliant: access control, logging, retention and the Act’s duties follow the system, not the hosting. Sovereignty reduces one risk class. It does not replace governance.
Three: the cost question, done honestly. The headline numbers favour local: cost differences of six to sixty times per million tokens between open and closed models are being reported by infrastructure providers[1]. But per-token maths is exactly the trap we warned about in a previous piece, the real comparison is total cost per completed workflow: hardware, energy, engineering time, model updates, and the price of a wrong answer. At sustained high volume with stable workloads, local usually wins. At low volume or fast-changing use cases, the API often stays cheaper than the engineers you would hire.
| Closed frontier API | Local open-weight | |
|---|---|---|
| Data residency | Contractual | Physical: inside your perimeter |
| Cost profile | Low entry, scales with usage | High entry, cheap at volume |
| Operations burden | Vendor’s problem | Your problem, permanently |
| Capability | Frontier | Roughly three months behind |
| Dependency risk | Restriction hits instantly | You control the off switch |
What I see in the field
In a DAX headquarters environment and among mid-sized owners I see the same two failure modes. Some move local out of principle and discover they have bought themselves an infrastructure team they never wanted. Others stay closed out of convenience and rediscover the dependency problem the hard way. The teams that get it right decide workload by workload: sensitive and stable goes local or EU-hosted, exploratory and fast-moving stays on APIs, and they wrote that decision down before any vendor entered the room.
What this means for you
Run the three checks in order: technical readiness on site, a real data protection assessment, and cost per completed workflow rather than per token. Treat hybrid as the default answer, not the compromise. And decide the deployment model after you know the workload: never before.
This assessment: readiness, data protection, honest cost maths per workload: is literally what our AI Readiness Audit produces, and keeping the buy-versus-host decision current as models shift is what the AI Decision Partner is for. Vendor-neutral on this question by design: we sell no infrastructure and no API.
Personalised answer within 48 hours.
Sources
- SiliconANGLE, Open-Weight AI Models Drive Shift to Data Control (RAISE Summit coverage), 14 July 2026. siliconangle.com
- VentureBeat, Enterprises Lost Claude Fable 5 for a Few Weeks: New Data Shows Two-Thirds Had Already Built Their Hedge, July 2026. venturebeat.com
- EU AI Act Implementation Timeline, artificialintelligenceact.eu. artificialintelligenceact.eu



The AI Act Just Moved. Your Deadline Did Not.